The Sovryn Treasury Theft
This dossier concludes that insiders stole value belonging to SOV stakers: the protocol’s usable treasury, FastBTC reserves financed with staker assets, and promised fee revenue. When FastBTC closed, 25.66 BTC from its visible Bitcoin and Rootstock reserve branches reached one exchange deposit address. A separate Exchequer route followed. Together, the traced FastBTC and Exchequer assets place an estimated $5.21–$5.34 million at issue from 21 November 2025 through 24 January 2026. Linked SOV-backed loans separately harmed RBTC lenders.
+ 23.1464 RBTCFastBTC’s likely shutdown inventory, followed by the separate Exchequer source route; both converged at the same Bitcoin exchange deposit address
+ 12,215 ZUSDremoved from stakers’ claim accounting by the measured snapshot after Sovryn promoted BTC income
What SOV stakers lost
SOV stakers are Sovryn’s governance. Staking gives them voting power and a share of protocol fees. This case documents two losses to SOV stakers; the loan record separately concerns RBTC lenders.
- Shared treasury and FastBTC reserves
- FastBTC received 100 BTC authorized from the treasury and another 34.5001 RBTC financed through loans against Exchequer and Exchequer-routed SOV. At shutdown, 25.66001145 BTC from its visible reserve branches reached one exchange address. Usable Exchequer assets—including 23.1464 RBTC worth about $2.12 million when transferred—were then routed out separately.
- Protocol-fee revenue
- Promised RBTC and ZUSD fee revenue was removed from the claim-accounting entries SOV stakers use to collect it.
- RBTC lenders
- Linked borrowers drew Bitcoin against thin SOV collateral, leaving a modeled 4.0441-RBTC lender-pool shortfall and later liquidations.
What happened, in eight steps
The dated sequence runs from concentrated wallet control and staker-financed FastBTC reserves through the shutdown sweeps, Exchequer exits, removed protocol-fee revenue, linked loans, notice, and blocked recovery.
Terms used in this dossierOpen the wallet, asset, and governance glossary
- RBTC, WRBTC, and iWRBTC
- RBTC is Bitcoin represented on Rootstock. WRBTC is its contract-compatible form. iWRBTC is Sovryn’s RBTC lending-pool contract and receipt token.
- SOV stakers
- People who lock SOV to vote in Sovryn governance and receive a share of protocol fees. Longer locks can carry more voting weight. The Exchequer holds shared treasury assets for the protocol.
- Address or wallet
- A blockchain account identified by a public address. The address shows transactions; a signing key controls what it can send.
- Exchequer multisig
- SOV stakers’ shared treasury wallet. A multisig requires a minimum number of registered owner-addresses to approve a transaction; three approvals were required during the treasury transfers studied here.
- Bitocracy and SIP
- Bitocracy is Sovryn’s SOV-weighted proposal and voting system. A SIP is a Sovryn Improvement Proposal submitted to that system.
- FeeSharingCollector
- The contract that recorded and distributed protocol fees to SOV stakers as an economic incentive for governance. Its replaceable code and administrative controls are central to this case.
- ZUSD and USDt0
- Dollar-linked stablecoins used in the fee and incentive-program records.
- Governor and Guardian
- Sovryn’s Governor contracts process governance proposals. A Guardian shared wallet holds emergency administrative powers over them.
- B7 cluster
- A strict group of 73 addresses whose first recorded funding paths lead to B7. The set includes wallets later used in Exchequer, governance, and FastBTC administration; repeated synchronized activity establishes one centrally directed operation.
- Recurring wallet labels
- B7 is the common funding wallet; D9 is the Rootstock-to-Bitcoin transit wallet; 8C is the Tyrone-linked conversion, routing, and Safe-deployment wallet; DD names matching 2-of-5 destination and payment Safes on Ethereum and BNB Chain whose five-owner set is also used across the official BOS token-control network; and 0xfEE171…4a9e7e is the FeeSharing deployment and Exchequer-submission wallet named in Tyrone’s official deployment record.
- Exchange pool
- A reserve pool—also called an automated market maker, or AMM—that sets a token’s sale price. A large sale receives progressively less as it drains the available Bitcoin.
-
One coordinated setup became many wallets
A shared wallet requiring two of three owners funded common funding wallet
See the seed and wallet proofB7 · 0xb7d16f…ed81d8, which then paid the first transaction fees for scores of addresses. Ten previously unused core wallets sent their first outgoing transaction straight back to B7 within minutes. On a holder list they look separate; their two-way setup and later synchronized activity establish a centrally directed operation. -
The lending-pool conversion pattern began years earlier
The Exchequer and one of its registered owner-addresses drew 34.5001 RBTC through four direct SOV-backed borrows. All four payouts reached FastBTC; none recorded a borrower-funded repayment or added collateral, and their debt was ultimately satisfied through 62 liquidations and two collateral swaps. A separate 2022 leveraged SOV position then carried linked lender exposure forward and now accounts for most of the cluster’s modeled shortfall.
Follow the earlier loan record -
BOS sale receipts entered a shared operations network
Origins recorded a $4.89 million USD-valued sale counter. Public-chain reconstruction represents about $4.17 million at a matched daily-market benchmark, including high-confidence Bitcoin and Cardano collector pools. BOS receipts entered 0x509201, Sovryn’s Exchequer, and exchange routes later reused by Exchequer-derived funds.
Follow the cross-project fund paths -
FastBTC closed and 25.66001145 BTC reached one exchange address
The visible shutdown inventory left through three reserve branches: 8.15166231 BTC from the BTC-to-RBTC replenisher wallet family, 6.37841068 BTC from the RBTC-to-BTC payout multisig, and 11.12993846 BTC through Rootstock peg-outs. On the Rootstock branch, an Exchequer owner linked to B7 by its first recorded funding submitted the first material transfer into D9; two FastBTC owners with the same B7 funding link approved the second. Four net receipts converged at one exchange deposit address without a public closing reconciliation for the staker-financed reserve.
Follow both sides of the bridge -
SOV stakers’ usable treasury assets were stolen into the same financial network
Thirty-three material operations were used to move RBTC and other reserves through a small set of routes. Every operation received the required approvals from at least three registered owner-addresses of the Exchequer multisig. Later tracing shows exact Bitcoin and Ethereum exchange infrastructure reused across BOS sale and Exchequer-derived routes.
Follow the treasury exits -
Stake moved, four loans opened, staker revenue was stolen
Seven B7-first-funded wallets withdrew approximately 10.05 million SOV from matured stakes in 1h52m24s. Four of them then opened loans inside 15m12s, supplying approximately 7.01 million SOV in the borrow calls for 1.465 RBTC in net payouts. Yago’s reward-pause announcement of the change documented here as theft followed the last opening by 12h35m, placing the loan session and policy change in one tightly ordered sequence.
See the synchronized sequence -
Users warned leadership; the positions stayed open
The transactions and lender risk were published. On Call #73, Yago said, “What’s it got to do with me?” He later called the loan link baseless and characterized the broader exchange as “conspiratorial thinking” and “noise.” The located public record contains no commitment to require repayment, pause affected lending, pursue any available protective action, or investigate the positions; linked voting defeated the executable recovery.
Hear the response and inspect the loans -
Value reconverged; lenders remained exposed
Borrower balances came back together, and cluster value reached USDt0 campaign signer
Follow the campaign-funding pathde169 · 0xde1690…5f6af2current registered owner-address of Sovryn’s 0x924f Exchequer multisig, which also guards both Governor contracts . That wallet later funded a USDt0 incentive campaign. August liquidations followed. At the 18 August measurement point, all five material cluster-linked positions remained active and below Sovryn’s required collateral level.
Search the evidence
Search by person, wallet, asset, proposal, or transaction. Every result returns to its original context and source record.
How findings are labeled and reproduced
We reconstructed transactions and contract balances directly from the named blockchains. Every current balance is tied to one stated block and time; this is a “pinned snapshot.” The public packet identifies any outside index used to find older or cross-chain records and provides the inputs needed to rerun each calculation.
- On-chain record
- A transaction or contract state stored on a blockchain.
- Direct source record
- A dated post, document, code artifact, image, or recorded statement attributable to its source.
- Dossier conclusion
- The finding drawn from the records identified beside it.
- Records authorities should compel
- Private evidence that should be preserved and obtained through lawful process.
“Dossier conclusion” identifies this publication’s evidence-based finding. The record supports a referral for suspected fraud, misappropriation, and related offenses. Courts and authorities determine charges and liability after compulsory process.
Reader-facing precision: token amounts and percentages are rounded to economically meaningful precision so the story remains legible. Search fields, linked explorers, source JSON, and the downloadable evidence packet preserve the exact underlying values.
0 matching records
0 sections · filed in dossier order
Select a record to inspect it in its original context.
No indexed evidence records match
Try a different person, address, proposal, asset, or transaction hash.
Try a known term:
Inspecting a matched record.
Four public notices that put leadership on notice
These disclosures establish what leadership was told and when. The underlying transactions, contract states, and calculations supply the technical proof below.
Disclosure #1
Public Disclosure #1 — Exchequer RBTC to exchange-style cluster (opens in a new tab)
First published the RBTC route and asked leadership to explain it.
Disclosure #2
Public Disclosure #2 — Founding-member SOV collateral loan (opens in a new tab)
Identified the four linked loans, warned of lender risk, and asked that they be closed.
Disclosure #3
Public Disclosure #3 — Exchequer total assets withdrawn (opens in a new tab)
Expanded the inquiry from RBTC to the usable treasury and challenged the FastBTC account.
Disclosure #4
Public Disclosure #4 — SOV loans liquidate, bad debt, and profit trail (opens in a new tab)
Recorded August liquidations, continuing impairment, and the subsequent borrower-cluster value trail.
Pinned records control every published figure. The dossier uses the block snapshots, transaction records, measurement definitions, and tracing methods in the downloadable public packet.
Part I · Control and treasury theft
How control was concentrated—and treasury assets left
The record shows advance control, repeated multisig execution, specific notice, blocked recovery, retrospective ratification, and measurable harm to SOV stakers and RBTC lenders.
The evidence links pre-existing operational control to theft of SOV stakers’ shared treasury assets and fee rights, coordinated lending exposure, dismissal after specific notice, and governance action that preserved and later ratified the disputed change.
Control record
One funding root operated many apparent holders
Sovryn marketed direct Bitocracy control and user ownership while decisive powers remained with operational multisigs and a concentrated funding-and-voting network.
Statement
Public materials described a system directly controlled by Bitocracy and owned by its users, in which no single entity could make crucial changes.
Yago’s Bitocracy essay (opens in a new tab) · Sovryn fundraising statement (opens in a new tab)
Record
Exchequer retained both FeeSharing owner powers from October 2021. The live Guardian did not receive SIP-0047’s published seven-owner set. A strict B7-first-funded set supplied approximately 67.7% of source-attributed voting power.
See who can change Sovryn’s contracts now
The live control register checks reviewed Sovryn contracts across lending pools, AMMs, core systems, Zero, Mynt, bridges, and Perimeter. It also asks the lending and AMM registries for their current members. Contracts with a high-impact control outside the two Bitocracy timelocks appear first; unanswered checks remain clearly marked.
Concentration snapshot: Rootstock block 9,162,625 · 18 Aug 2026 17:55:21 UTC. Reader-facing percentages are rounded; the packet preserves the exact fixed-point result.
How one funding root became many apparent holders
Splitting tokens and votes among addresses can create the appearance of diversification in a holder list. The audit tests whether those addresses were operated together: one source paying their first transaction fees, immediate return transactions, long dormancy broken in common sessions, exact-value handoffs, aligned votes, and synchronized staking and borrowing.
The seed
shared wallet requiring two of three owner approvals at funding B7 origin wallet · 0x777e7f…aaf97f sent 0.01 RBTC and then 5.89 RBTC to common first-funder and coordinated-cluster root B7 · 0xb7d16f…ed81d8 on 20 November 2020.
0.01-RBTC funding transaction (opens in a new tab) · 5.89-RBTC funding transaction (opens in a new tab)
- B7 origin-wallet approvals
- Two of three owners were required when it funded B7. The recovered approvals on both transfers were supplied by origin-wallet creator and co-signer
01ad · 0x01ad90…9dd990and origin-wallet co-signer and transaction submitterde25 · 0xde25ca…afc827. - B7 activity
- 134 indexed transactions, including 94 successful simple transfers to 69 recipients. Under the packet’s strict rule, the confirmed set contains 73 addresses including B7: 55 first funded directly and 17 first funded through intermediate wallets. Ten other wallets are excluded because the public index could not establish their first transaction.
- Two-way setup record
- Ten previously unused core wallets funded in the February 2021 batch made their first outgoing transaction straight back to B7 only 1m13s–6m20s later. Their transaction-fee settings fall into three repeated groups.
- What this establishes
- Ten newly activated wallets sent value back to B7 within 73–380 seconds as their first outgoing transaction, using the same transfer limit and three repeated transaction-fee groups. This establishes one coordinated setup session.
Transaction record
Common first funding; one uninterrupted funding batch; ten immediate return transactions; repeated transaction-fee settings; exact-value handoffs; multi-wallet staking bursts; synchronized February withdrawals and restakes; concentrated, aligned voting; and later borrower-value consolidation.
Coordination finding
The complete histories establish a centrally directed B7 operation. Low-frequency wallets repeatedly executed the same economic actions in narrow windows after long periods of inactivity.
Responsibility chain
Public records place Yago, Nahari, and Tyrone in the leadership, accounting, and implementation roles surrounding this coordinated operation. Authorities should obtain custody logs, devices, delegate instructions, and communications to allocate each key and instruction.
Inspect the ten first outgoing return transactions to B7
| Wallet | B7 funding | First outgoing transaction | Returned | Delay | Transaction-fee price |
|---|---|---|---|---|---|
February borrower; later RBTC hub b493 · 0xb493b1…a2c155 | B7 outgoing transaction #51 (opens in a new tab) 12:01:06 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 1m 40s | 18387381 |
February borrower 5011 · 0x50110e…f07962 | B7 outgoing transaction #53 (opens in a new tab) 12:05:31 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 3m 4s | 18387381 |
Large staker; transfer intermediary; recovery-opposition voter 78a0 · 0x78a0de…c0ffa7 | B7 outgoing transaction #54 (opens in a new tab) 12:12:54 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 1m 13s | 18387381 |
February borrower 91ab · 0x91ab7f…021684 | B7 outgoing transaction #55 (opens in a new tab) 12:16:46 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 2m 46s | 18387381 |
February borrower; former registered owner-address of the 0x924f Exchequer multisig; exact 2022 SOV handoff 4f39 · 0x4f3948…ae2e97 | B7 outgoing transaction #56 (opens in a new tab) 13:09:53 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 3m 29s | 8468389 |
2022 leveraged SOV-position borrower; large staker; recovery-opposition voter 8d51 · 0x8d5158…be0fb7 | B7 outgoing transaction #58 (opens in a new tab) 13:18:52 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 1m 32s | 8468389 |
Large staker; recovery-opposition voter; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e) a738 · 0xa7388d…3edce6 | B7 outgoing transaction #59 (opens in a new tab) 13:32:47 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 6m 20s | 1008468389 |
Large staker; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e) 9369 · 0x93698c…08a12e | B7 outgoing transaction #61 (opens in a new tab) 14:01:42 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 4m 21s | 8468389 |
Large staker; recovery-opposition voter 0d18 · 0x0d1831…238e91 | B7 outgoing transaction #62 (opens in a new tab) 14:18:43 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 1m 14s | 1008468389 |
Current registered owner-address of the 0x924f Exchequer/Governor-guardian multisig and Contracts Guardian shared wallet dfd4 · 0xdfd4da…1eba62 | B7 outgoing transaction #63 (opens in a new tab) 14:22:02 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 1m 29s | 1008468389 |
Why this is stronger than common funding: B7 paid the first transaction fees for ten recipients, and every recipient returned value to B7 within 73–380 seconds as its first outgoing transaction. Every return used the same simple-transfer limit, and the fee prices fall into three repeated groups. Together, those facts establish a coordinated setup session.
Inspect the complete-history activity profile
| Wallet and role | Outgoing transactions | Transaction-number range | Transactions other than votes | Active days other than voting | Longest outgoing gap (rounded) |
|---|---|---|---|---|---|
b493 February 2026 borrower | 53 | 0–52no missing outgoing nonces | 22 | 12 | 301 days |
5011 February 2026 borrower | 55 | 0–54no missing outgoing nonces | 26 | 9 | 297 days |
78a0 large staker · transfer intermediary | 36 | 0–35no missing outgoing nonces | 20 | 8 | 297 days |
91ab February 2026 borrower | 26 | 0–25no missing outgoing nonces | 21 | 10 | 512 days |
4f39 February 2026 borrower · former owner of the 0x924f Exchequer multisig (2021–2023) | 551 | 0–550no missing outgoing nonces | 527 | 176 | 298 days |
8d51 legacy borrower · large staker | 88 | 0–87no missing outgoing nonces | 57 | 25 | 282 days |
a738 large staker | 46 | 0–45no missing outgoing nonces | 16 | 11 | 297 days |
52e8 former owner of the 0x924f Exchequer multisig; every outgoing transaction confirmed one of its transactions | 49 | 0–48no missing outgoing nonces | 49 | 8 | 11 days |
9369 large staker | 40 | 0–39no missing outgoing nonces | 22 | 9 | 409 days |
0d18 large staker | 65 | 0–64no missing outgoing nonces | 24 | 13 | 297 days |
dfd4 current owner of the 0x924f Exchequer/Governor-guardian multisig and the 0xdd8e Contracts Guardian shared wallet · large staker | 52 | 0–51no missing outgoing nonces | 38 | 18 | 398 days |
How activity was counted: the table covers complete Blockscout histories of transactions started by each address. Contract-generated transfer records are not counted again as separate wallet transactions. The result shows low-frequency wallets repeatedly making the same economic moves together after long inactive periods.
Open the linked-wallet explorer directory
0xb7d16f650cb3b0754d61bdb3f6db79157ded81d8 Common first-funder and coordinated-cluster root0x91ab7f5df554566a8cdd2cfc722d0aa031021684 February borrower0x4f3948816785e30c3378ed3b9f2de034e3ae2e97 February borrower; former registered owner-address of the 0x924f Exchequer multisig; exact 2022 SOV handoff0xb493b1fb97f4cb2a1ea43a9ffed201e797a2c155 February borrower; later RBTC hub0x50110ef4e85a6a2e00a37d2eb30062000df07962 February borrower0x8d515805a21743c2f2f33aa12a420907cbbe0fb7 2022 leveraged SOV-position borrower; large staker; recovery-opposition voter0x78a0de7a48cce1a8759f353987731394d5c0ffa7 Large staker; transfer intermediary; recovery-opposition voter0xa7388d112406412f68c14e2924a070fd893edce6 Large staker; recovery-opposition voter; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e)0x52e8f03e7c9c1ef320ff7c31db78eaead18e5f85 Former registered owner-address of the 0x924f Exchequer multisig; every outgoing call confirmed one of its transactions0x93698c0150d17b98b820e9c2fdcfa161d508a12e Large staker; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e)0x0d1831ed7f1c5c55409a542d7e4bdda0c1238e91 Large staker; recovery-opposition voter0xdfd4da0e0e656af349e192b954baaef0fc1eba62 Current registered owner-address of the 0x924f Exchequer/Governor-guardian multisig and Contracts Guardian shared wallet0xa7a4a1afefdeadcb287769562fb65c3bbd83ccb6 Recovery-opposition voter; February restaker0xde1690480ef789beaa112157c7d123a5c85f6af2 Current registered owner-address of the 0x924f Exchequer/Governor-guardian multisig; FeeSharing approver; campaign signerThe complete 73-address attribution file publishes every full address, first-funding path, proof transaction, balance, and voting value. The complete-history coordination packet publishes the setup callbacks, address activity metrics, synchronized sessions, February linkage, methodology, and responsibility-record targets.
Common funding and coordination
Four February borrowers, the 2022 leveraged-position borrower, large stakers, and a former Exchequer multisig owner were funded in one uninterrupted run of B7 transactions. In 2022, February borrower and former Exchequer multisig owner 4f39 · 0x4f3948…ae2e97 sent approximately 385,915 SOV to 2022 leveraged-position borrower 8D51 · 0x8d5158…be0fb7 ; within 4m57s, 8D51 put the same underlying amount into three loan positions. The packet preserves the exact equality. Inspect the handoff (opens in a new tab) .
Guardian discrepancy
Zero of SIP-0047’s seven published Bitocracy Guardian signers was added to the live Guardian. In June 2026, Tyrone’s published role wallet sent and co-signed a valid owner rotation adding new owner wallets.
Allocate the coordinated operation
Authorities should obtain signer custody, delegate instructions, internal vote coordination, device/IP logs, and ownership records to assign each key and instruction within the established coordination pattern.
Treasury record
Treasury assets were stolen through repeated Exchequer multisig approvals
FastBTC’s visible Bitcoin and Rootstock reserves converged at one exchange address during its November 2025 shutdown. From 4 December 2025 through 24 January 2026, 33 material Exchequer operations then followed a small set of recurring routes, each using the ordinary three-owner approval process.
Route explorers: Exchequer multisig 0x924f · 0x924f5a…2dc711 · Rootstock-to-Bitcoin transit wallet D9 · 0xd9ecb3…0a5d89 · conversion and bridge wallet 8C · 0x8c9143…84f50b supplied by the displayed Tyrone project account during the on-chain-matched May 2024 session · destination shared wallet on Ethereum DD · 0xdd2311…ee3fc4 · matching destination shared wallet on BNB Chain DD · 0xdd2311…ee3fc4 · FeeSharing deployment and Exchequer-submission wallet 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record
Value when the RBTC left the Exchequer: approximately $2.12 million. Using the closing BTC-USD price in the one-minute Coinbase Exchange candle containing each execution, 12 RBTC on 4 December 2025 was worth about $1,121,736; 6.7298 RBTC on 22 January 2026 about $605,630; and 4.4166 RBTC on 24 January 2026 about $395,314. Combined transfer-time estimate: $2,122,679.92. 4 December price (opens in a new tab) · 22 January price (opens in a new tab) · 24 January price (opens in a new tab) · method and arithmetic.
Treasury-linked DLLR redemptions forced Zero borrowers to surrender Bitcoin exposure
The investigation began with a narrower concern: treasury-linked DLLR was being turned into RBTC through Zero in a way that reduced Sovryn customers’ Bitcoin collateral exposure. At that point, the investigator did not yet know that the redemptions sat inside a much larger theft of usable treasury assets.
- 1Customers deposited BTC and borrowed a stablecoin.
A Zero customer locked RBTC in a Line of Credit and minted ZUSD against it. DLLR could be converted into its backing asset, ZUSD.
- 2Treasury-linked value took the protocol-redemption route.
Five Exchequer transactions sent approximately 569,214 DLLR to 8C. That wallet made matching DLLR-to-ZUSD calls and then eleven successful Zero
redeemCollateralcalls. First Exchequer DLLR exit (opens in a new tab) · last Exchequer DLLR exit (opens in a new tab) . - 3Zero allocated the redemption against borrowers.
Unlike an automated-market-maker sale, Zero’s redemption design (opens in a new tab) cancels the redeemer’s ZUSD and removes the oracle-priced RBTC equivalent from active Lines of Credit, beginning with the lowest-collateralized eligible positions. First successful Zero call (opens in a new tab) · last successful Zero call (opens in a new tab) .
Why that harmed Sovryn customers
Zero forced the timing of the collateral reduction. Each redemption reduced both debt and BTC collateral at the redeemer’s chosen moment, taking from borrowers the Bitcoin exposure they had used Zero to preserve.
The route also contracted ZUSD/DLLR supply instead of helping it grow. The dossier concludes that using treasury-controlled assets this way prioritized treasury conversion over minimizing harm to the protocol’s own users.
Attribution supported by the transaction record
The curated sequence records five treasury DLLR exits, five aggregator calls, eleven successful Zero redemptions, and approximately 6.2281 RBTC returned after the batches. The successful redemption inputs exceed the identified treasury DLLR because 8C held commingled balances. The attributable finding is a treasury-linked sequence; commingling prevents allocation of every redeemed ZUSD unit or returned satoshi solely to Exchequer DLLR.
Inspect the full transaction sequence and attribution limit.
Yago’s explanation
Yago later described the activity as an “overall consolidation that we did of the treasury.”
The question specifically raised the December–January DLLR conversions. Yago said Sovryn wanted to hold most treasury funds in BTC because “the project does the same.” Community Call #72, beginning at 43:52 and continuing at 46:40.
What the public wallet record showed
By the time of the call, the Exchequer multisig held only 0.7134 RBTC. The record traces approximately 23.1464 RBTC—worth approximately $2.12 million when the three transfers left the Exchequer—through the Rootstock-to-Bitcoin transit wallet (D9) to one exchange account address. Confirmed Exchequer-derived DD receipts comprise 522,242.076079 official stablecoins, 44.109475650313137836 ETH, and 52.853639178690725711 BNB. Separately, 10.949 WETH remains at 8C on BNB Chain, while the far side of the distinct 46.01-ETHes request remains unlocated. No public ledger has reconciled those off-wallet holdings back to Sovryn.
The description of consolidating the treasury into BTC does not match the visible destinations and asset mix. All 33 operations used valid Exchequer multisig approvals. FeeSharing deployment wallet and Exchequer signer; 33 approvals 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record approved all 33. Three other registered Exchequer owner-addresses— Exchequer owner-address; 25 approvals 0x9e9c0a…5dcf22 · 0x9e9c0a…5dcf22 , Exchequer owner-address; 23 approvals 0xa0fdcd…30ed8b · 0xa0fdcd…30ed8b , and Exchequer owner-address; 18 approvals 0xeabb83…152a86 · 0xeabb83…152a86 —completed the active signer group.
Destination reconciliation—not another addend. DD received 508,947.877906 USDT and 13,294.198173 USDC, totaling 522,242.076079 official stablecoin units; 44.109475650313137836 ETH; and 52.853639178690725711 BNB. Across the six ETH-wrapper exits, 31.989275650313137836 ETH reached DD and 10.949 WETH remains at 8C. The source-exit values are counted once in the estimate; these destination balances, fees, and bridge differences are not added again. The separate 46.01-ETHes source request remains upper-only because its far-side receipt has not been located. Inspect the conservation record.
Complete question and answer describing overall treasury consolidation
Watch the full Community Call #72 on YouTube (opens in a new tab) · source recording and captions checked
Inspect the underlying DD and BOS custody record
Cross-project custody record
The DD treasury destination shares its control network with BitcoinOS
DD received assets routed from Sovryn’s Exchequer. Matching DD Safes on Ethereum and BNB Chain were configured with the same five owner addresses as the Safe that owns the official BOS token and the Safes holding BitcoinOS’s published allocation buckets. The record establishes shared custody, signer, deployment, and payment infrastructure across Sovryn treasury activity and BitcoinOS token administration.
- Separation asserted; a contribution path contemplated
Yago wrote, “Sovryn has not been funding BitcoinOS” (opens in a new tab) , described separate contributors and funding, and later said “Sovryns treasury is not being requested for anything.” (opens in a new tab) He repeated the distinction on Community Call 63 (opens in a new tab) . On 2 July he added that, for Sovryn to receive 10%, it would need to “invest between $5m-$100m in value or provide in-kind value to that degree” (opens in a new tab) and actively help raise BOS funds.
- Official contributions acknowledged
SIP-0083 (opens in a new tab) said Sovryn had made substantial contributions throughout BitcoinOS development and committed Sovryn resources to technical development, audits, interfaces, marketing, infrastructure, and network operations. Yago then called Sovryn a significant BitcoinOS participant (opens in a new tab) .
- Cross-payments admitted; mingling denied
Yago said funds had been “paid out by BOS on behalf of Sovryn” (opens in a new tab) and needed year-end consolidation. Minutes later, asked whether Sovryn was mingling funds with BOS, he answered “No.” (opens in a new tab) The shared-key and payment record below requires a transaction-level reconciliation of those statements.
Asset route
- Sovryn Exchequertreasury-derived assets
- 8C and bridge routesconversion and deployment layer
- DD on two chains2-of-5 destination and payment Safes
Owner-address linkage across time
- B7Rootstock · Dec 2020 · 0.1 RBTC
- 0x509201…AbD6cross-chain operations address
- 0x5C07…96C2Ethereum first funding · Oct 2025 · 0.05 ETH
Control overlap
- 8C deployerDD and BOS Safe families
- Same five owner addressesrepeated 2-of-5 control set
- BOS administrationtoken owner and allocation Safes
01 · One control set
DD and the BOS Safe family use the same five owner addresses
8C created Ethereum DD (opens in a new tab) 63 seconds after creating its matching BNB Chain Safe (opens in a new tab) , using identical setup data, the same five owners, and a 2-of-5 threshold. The same 8C wallet created the Safe that owns the official Ethereum BOS token (opens in a new tab) and the allocation Safes with that exact owner set.
The initial BOS balances reconcile the official schedule: 6.72 billion BOS, exactly 32%, reached the inferred ecosystem Safe; three inferred founding-entity Safes received 7.35 billion BOS, exactly 35%, after accounting for their 100-BOS tests and 50-BOS returns. Official allocation schedule (opens in a new tab) · allocation execution (opens in a new tab) .
Track the current balances and every reviewed movement from the BOS allocation and treasury wallets. The live register separates direct transfers, exchange-address routes, bridges, lending activity, purchaser distributions, and destinations that still require classification.
02 · Long-running operational continuity
0x509201…AbD6 links B7, Sovryn’s bridge, payments, DD, and BOS
B7 sent 0.1 RBTC to 0x509201…AbD6 in December 2020 (opens in a new tab) . The same address later sent at least 8.55 million USDT across 18 transfers to the official Sovryn Ethereum bridge (opens in a new tab) , solely controlled an earlier recurring-payment Safe, approved every observed Ethereum DD execution, and is listed throughout the BOS Safe family.
Five external recipients from that earlier CSV-style recurring-payment record (opens in a new tab) reappeared together in DD’s December 2025 batch. That functional continuity is stronger than a shared-wallet-format resemblance: it connects the operator key and recipient network across years.
The BOS sale-wallet reconstruction establishes direct proceeds links: the post-maintenance Ethereum collector transferred 204,103.50752 USDT, 30,056.588245 USDC, and 3.605528 ETH to 0x509201, while its Rootstock instance sent swept participant RBTC into Sovryn’s Exchequer.
03 · Concentrated execution
The same pair approved all 14 Ethereum DD executions
0x509201…AbD6 and 0xcD9003…fBAA supplied every observed Ethereum DD quorum. DD then sent 70 ETH on 1 December 2025 (opens in a new tab) and 120,000 USDT on 30 March 2026 (opens in a new tab) directly to 0x509201…AbD6; the recipient approved both payments and 0xcD9003…fBAA supplied the second signature.
On BNB Chain, DD’s executed transaction used 0x509201…AbD6 with 0x5C07…96C2 . The five addresses are Safe owner addresses, not five identified independent people.
Inspect the five owner addresses and their demonstrated roles
| Owner key | Evidence-based role | Demonstrated basis | Human controller |
|---|---|---|---|
0x5092019A3E0334586273A21a701F1BD859ECAbD6 | Long-running Sovryn and BitcoinOS treasury-linked operational owner address; recurrent DD signer and DD payee Confidence: very high | Received RBTC from B7; sent 18 USDT transfers totaling 8,550,668.522386 USDT to Sovryn's official Ethereum bridge; solely controlled the earlier recurring-payment Safe; provisioned three later shared owner addresses; approved every Ethereum DD execution; received 70 ETH and 120,000 USDT from DD; and is listed throughout the BOS Safe family. | unidentified |
0xcD90036b1b1E2576E380Fa407Cb8021f4f4efBAA | Principal BitcoinOS/DD owner address and recurrent DD co-signer Confidence: very high | Supplied the second approval on every observed Ethereum DD execution and is listed throughout the related BOS and DD Safes. | unidentified |
0x5C07E4CC17e3d6076fc7963235B1e3299b1596C2 | Shared DD/BOS owner address and BNB DD co-signer directly provisioned by 0x509201…AbD6 Confidence: high | Co-approved the observed BNB Chain DD execution and is listed throughout the DD/BOS Safe family. The address has no located Rootstock activity; its B7 relationship is the proved two-hop path through 0x509201…AbD6. | unidentified |
0xe31cfdF3C6E4FE91f8873227e025725bb9dF67C6 | Lightly used shared DD/BOS owner address provisioned by 0x509201…AbD6 Confidence: high | 0x509201…AbD6 supplied its first Ethereum funding; the address is listed throughout the exact five-owner DD/BOS Safe family. | unidentified |
0x59c4d24687f5eE6C846Df010a49b55281d2Ded0f | Lightly used shared DD/BOS owner address provisioned by 0x509201…AbD6 Confidence: high | 0x509201…AbD6 supplied its first Ethereum funding; the address is listed throughout the exact five-owner DD/BOS Safe family. | unidentified |
What leadership said when the customer harm was asked directly
On Community Call #73, Yago was asked why the treasury route redeemed against users rather than using another conversion path. He said he was not involved in that choice. Nahari said he could not recall the exact reason and suggested it might have concerned BabelFish liquidity.
Later in the same call, continued questions were characterized as baseless, conspiratorial, noise, bad faith, and a failure to understand—without a transaction-level ledger that reconciled the challenged routes.
Why the later record changes the meaning of those answers
The initial complaint concerned a specific customer-protection problem. Only later did the wallet record reveal the larger treasury theft and multiple destination routes. The explanations then expanded from ordinary consolidation into BTC, to exchange payments and a general FastBTC-liquidity account, while the reason for choosing Zero redemptions against users remained unreconciled.
This victim-led dossier concludes that the repeated omission of material context, shifting explanations, and dismissal of evidence amounted to deception and gaslighting. SOV stakers and RBTC lenders experienced each new discovery as another reason to doubt assurances they had already been given. The public record proves the statements and the unreconciled sequence; private communications and account records remain necessary to determine each person’s intent and instruction.
Complete question and answer containing the inability to explain the precise redemption method
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
Complete question and answer containing the bad-faith, lack-of-understanding, and no-deep-mystery response
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
FastBTC closed with 25.66001145 BTC sent to one exchange address
FastBTC’s visible shutdown inventory left through three operating branches: the BTC-to-RBTC replenisher wallet family, the RBTC-to-BTC payout multisig, and the Rootstock reserve. Four net Bitcoin receipts converged at one exchange deposit address during the announced November 2025 sunset.
Complete question and answer containing the general third-party FastBTC explanation
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
What Nahari said about the missing reserves
He said Sovryn’s systems needed roughly 80–100 BTC during 2025, that “a lot” was not Exchequer money, that some FastBTC funds came from third parties, and that funds had to return to original liquidity providers after sunset.
He identified no provider, agreement, amount, liability date, wallet, invoice, or transaction matching the challenged transfer.
Staker financing and shutdown record · 2021–2025
SOV stakers financed FastBTC
SIP-0012 (opens in a new tab) authorized 100 BTC from the Origin treasury for FastBTC. The Exchequer and its then-owner address 4f39 separately drew four net iWRBTC payouts totaling 34.5001 RBTC; every payout raised FastBTC’s 2021 BTC-to-RBTC user-payout reserve FastBTC’s production wallet · 0xca1c5b…6f147f by the exact amount.
The borrowers recorded no added collateral or borrower-funded CloseWithDeposit repayment. Their debt was satisfied through 62 liquidations and two collateral swaps against pledged SOV. At shutdown, the chain records 25.66 BTC moving from FastBTC’s visible operating branches to one exchange deposit address. No public closing ledger reconciles that destination against the staker-financed capital, accumulated fees, user exchanges, or the asserted outside providers.
FastBTC’s material Rootstock shutdown transfers trace to the B7 operation. The Exchequer owner 0xfEE171…4a9e7e —whose first recorded funding came through B7-linked C0AA—submitted the transaction that sent 4.0571 RBTC from FastBTCBridge to D9 (opens in a new tab) . FastBTC owners 0x986c…29d8 and 0x50e1…bb4e , whose first recorded funding paths lead to B7, supplied two of the three approvals for the 7.0631 RBTC production-wallet transfer to D9 (opens in a new tab) . Those two transfers supplied nearly all of the Rootstock reserve sent into D9 before 11.1299 BTC reached the exchange address.
- Treasury authorization
- 100 BTC
- Loan-financed reserve
- 34.5001 RBTC
- Visible shutdown receipts
- 25.66001145 BTC
- Shutdown destination
- One exchange address
Two episodes reached one terminal
The FastBTC shutdown and the later Exchequer route are analytically separate. Their convergence at one exchange address supplies a focused path for beneficiary tracing.
- 21–27 Nov 2025 · FastBTC shutdown
- 25.66001145 BTC four terminal receipts
- 4 Dec 2025–24 Jan 2026 · Exchequer route
- 23.1464 RBTC left the Exchequer for D9
The terminal received 48.79949643 BTC across the seven net receipts in these two episodes. That observed-receipt total is not an additional damages addend.
The 25.66001145-BTC figure is the likely FastBTC shutdown amount visible on-chain. The replenisher and payout address roles are operational reconstructions from official FastBTC architecture, multisig policy, transaction history, and matched bridge activity. The public record establishes staker financing, the three shutdown branches, and their common destination; the closing ledger must complete the economic allocation.
FastBTC’s shutdown reserves and the later Exchequer route converged at the same address
bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5 (opens in a new tab)
Nahari confirmed the destination type
“It is an exchange wallet. It has nothing to do with OKX.”
That Community Call #73 statement turns “exchange destination” from a third-party label inference into a direct management acknowledgment. Nahari then described centralized exchanges as being used to swap assets for payments and supplied the broader FastBTC-liquidity account.
What that admission supports
Nahari’s specific knowledge establishes that leadership recognized the exchange destination and asserted a business purpose for it. Exchange KYC and account records can identify the credited customer, beneficial owner, trades, withdrawals, and fiat proceeds.
OKLink labels the terminal address Gemini (opens in a new tab) . A directly connected consolidator carries an OKEx label on BitInfoCharts (opens in a new tab) . Together with Nahari’s explicit denial of OKX, Gemini is the leading public venue inference, not a settled identification. Exchange account and customer-identification records are required to resolve it.
| Reserve role | Bitcoin address or input family | Shutdown movement |
|---|---|---|
| BTC-to-RBTC replenisher reserve | 126 derived 2-of-3 P2WSH inputs (opens in a new tab) | 8.15192649 BTC in − 0.00026418 BTC fee = 8.15166231 BTC to the terminal |
| RBTC-to-BTC payout multisig | bc1qajsvfccw06h758pn3za8wcx7qjztarj53ejjp0rf5a34urmyp74s6psvg8 (opens in a new tab) | 6.37841992 BTC in − 0.00000924 BTC fee = 6.37841068 BTC to the terminal |
| Historical FastBTC staging/operator wallet | 18e3Ykzf2z8Xbc1qiDmxq5jPz6wRCwq429 (opens in a new tab) | Retained 0.45360411 BTC through the shutdown window; excluded from the four terminal receipts and the 25.66001145-BTC total |
| Rootstock peg-out staging | 1BVZ13Q7C66UUKsUUq3ReaauJsH9JXxQam (opens in a new tab) | 11.12993846 BTC reached the terminal in two net receipts after the D9 peg-outs |
| Common exchange terminal | bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5 (opens in a new tab) | 25.66001145 BTC from FastBTC’s four shutdown receipts; later used by the separate Exchequer route |
| Route | Terminal receipt (UTC) | BTC | Bitcoin transaction |
|---|---|---|---|
| FastBTC shutdown · BTC-to-RBTC replenisher operating family · 126 derived 2-of-3 addresses | 8.15166231 | 26022c0acb…875771 | |
| FastBTC shutdown · Rootstock reserve via D9 and PowPeg | 4.12996923 | 0d7c9836b5…9098e8 | |
| FastBTC shutdown · RBTC-to-BTC payout multisig | 6.37841068 | 3d45e407bb…7f84b9 | |
| FastBTC shutdown · Rootstock reserve via D9 and PowPeg | 6.99996923 | 8ee46e3c42…2f6703 | |
| December Exchequer route | 11.99899103 | 45f6e40a5c…d2b173 | |
| 22 January Exchequer route | 6.72047426 | f753d78eba…fba93e | |
| 24 January Exchequer route | 4.42001969 | dd5b45fe83…6efdc4 |
Distinct sources and one terminal address are proved; the exchange account remains to be identified. FastBTC’s four shutdown receipts total 25.66001145 BTC. The three later Exchequer receipts total 23.13948498 BTC after bridge fees. Together, the address received 48.79949643 BTC across the two episodes. Only the exchange can identify the credited customer, controller, trades, withdrawals, and beneficial owner.
Exchequer transaction ledger · 33 operations
| UTC / block | Asset / amount | Route | ID | Approvers | Execution |
|---|---|---|---|---|---|
#8,275,774 | ≈12 RBTC | D9 / PowPeg route Rootstock-to-Bitcoin transit wallet D9 0xd9ecb3…0a5d89 · 0xd9ecb3…0a5d89 | 2099 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xf09e5dde…a7d1d6 |
#8,276,441 | ≈200,000 XUSD | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2101 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x07052fa1…f4973c |
#8,277,370 | ≈202,460 XUSD | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2102 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0x78deb5f3…f57506 |
#8,277,710 | ≈200,000 MOC | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2103 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xeabb83…152a86 | 0x032087d6…29142e |
#8,279,785 | ≈363,500.89 MOC | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2104 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x495f862c…65ffd5 |
#8,290,267 | ≈0.14 ETHes | ETH bridge to DD (0.1302 ETH after fee) destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2106 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0xc6f569df…acddac |
#8,291,602 | ≈12 ETHes | ETH bridge to DD (11.99 ETH after fee) destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2114 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0xcaa7c69e…ad6c9a |
#8,297,226 | ≈0.1 ETHbs | BNB-chain WETH bridge to 8C (0.094 WETH after fee) conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2118 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xeabb83…152a86 | 0x9bb30ed5…078e65 |
#8,297,226 | ≈0.08 ETHs | Ethereum bridge to DD (0.067275650313137836 ETH after fee) destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2119 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xeabb83…152a86 | 0x3a5f59e8…5dee69 |
#8,298,372 | ≈0.05 ETHs | BNB-chain WETH bridge to 8C (0.049 WETH after fee) conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2121 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xeabb83…152a86 | 0x233dc970…6e64a4 |
#8,298,386 | ≈100,000 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2123 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0x2c78a6ef…13b41e |
#8,299,247 | ≈29 ETHs | BNB-chain WETH bridge to 8C (28.999 WETH after fee) conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2125 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0x2534bf7d…006a72 |
#8,299,254 | ≈2.8 ETHbs | BNB-chain WETH bridge to 8C (2.799 WETH after fee) conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2127 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0xee73a025…34c531 |
#8,299,259 | ≈2.09 BNBbs | BNB bridge terminal receipt 2.085 BNB destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2131 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0x42dcbd61…231e9a |
#8,299,262 | ≈0.78 BNBs | BNB bridge terminal receipt 0.772639178690725711 BNB destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2132 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0xbbc42bfc…f7cb65 |
#8,301,075 | ≈10.95 ETHs | BNB-chain WETH bridge to 8C (10.949 WETH remains at 8C) conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2134 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0xe76b9f95…c3f755 |
#8,301,076 | ≈100,000 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2135 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x298ea984…7bf16b |
#8,301,277 | ≈50 BNBbs | BNB bridge terminal receipt 49.996 BNB destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2137 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xd47074af…44e3fb |
#8,321,340 | ≈100,000 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2138 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x061e0602…aefc2b |
#8,324,949 | ≈794,380 SOV | FeeSharing deployment wallet and Exchequer owner-address0xfee171…4a9e7e | 2139 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0xeabb83…152a86 | 0x3c72607f…84282d |
#8,326,566 | ≈46.01 ETHes | ETH bridge request; far-side receipt not located destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2141 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0x4a4af853…7a2b02 |
#8,326,568 | ≈100,000 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2142 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0xa0b1bd1f…f65e61 |
#8,342,107 | ≈169,214 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2144 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x5661bbfa…0797fa |
#8,342,801 | ≈687,320 SOV | Exchequer owner-address 0x9e9c0a…5dcf220x9e9c0a…5dcf22 | 2145 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0x12dc23cb…adda6d |
#8,351,352 | ≈11,710 USDCes | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2151 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xab016cdb…8000ff |
#8,351,352 | ≈1,650 USDCbs | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2152 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0x87f9c88d…46b8ff |
#8,351,353 | ≈13,260 USDTes | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2153 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xeff95ec1…548ae5 |
#8,351,358 | ≈5,400 USDTbs | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2154 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xbf0f08ec…e446e9 |
#8,440,529 | ≈100,000 rUSDT | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2156 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0x8d135d4b…d433a9 |
#8,447,816 | ≈6.7298 RBTC | D9 / PowPeg route Rootstock-to-Bitcoin transit wallet D9 0xd9ecb3…0a5d89 · 0xd9ecb3…0a5d89 | 2157 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0xc9f566be…a96127 |
#8,448,302 | ≈3.65 BPRO | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2162 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0xea3646c2…4809a3 |
#8,448,306 | ≈55,000 DOC | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2163 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0x7c176380…080a12 |
#8,454,487 | ≈4.4166 RBTC | D9 / PowPeg route Rootstock-to-Bitcoin transit wallet D9 0xd9ecb3…0a5d89 · 0xd9ecb3…0a5d89 | 2164 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xeabb83…152a86 | 0x336a6d72…6bdd5f |
Opening priced-inventory cross-check for 1 December—not an addend. The complete registry-and-transfer audit produces a $3.32–$3.37 million priced minimum, including the approximately 5.07 million SOV balance marked at about $536,947, the ETHs and ETHbs positions, and $2,506 of retained DAIes, DAIbs, and BUSDbs at par. Retained BOS, MYNT, POWA, and WRBTC/BOS LP positions are disclosed but remain outside that dollar range because the record has no defensible USD mark for them. The later traced-flow estimate counts assets as they left and does not add this opening stock. BTC price (opens in a new tab) · ETH price (opens in a new tab) · BNB price (opens in a new tab) · all 24 positions, realized outputs, and valuation method.
By 18 August, the Exchequer multisig held 0.7134 RBTC, approximately 3.44 million SOV, the three retained dollar wrappers, and the disclosed unpriced positions; selling the entire SOV balance through the only identified exchange pool quoted approximately 0.5029 WRBTC. The priced liquid mix had been reduced to effectively no usable, diversified on-chain liquidity. The public packet keeps every input and values SOV separately so its thin market is not treated like cash.
Records needed to complete the treasury accounting
- Exchequer minutes, internal votes, budgets, and signer instructions
- Centralized-exchange customer-identification, subaccount, deposit-credit, trade, and withdrawal records for
bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5 - Signer identities and custody records for 8C and all five shared DD/BOS owner addresses, plus DD payee schedules, Safe execution records, and beneficial-controller mapping
- Sovryn and BTC OS Limited general ledgers, intercompany accounts, journal entries, cost allocations, reimbursements, invoices, payroll, processor contracts, and bank/exchange statements
- FastBTC’s production database, BTC deposit assignments, replenisher and payout wallet xpubs, signer instructions, shutdown approvals, opening and closing reserves, provider contracts and capital accounts, user liabilities, fees, rebalances, and transaction-level payment reconciliation
- Destination-side proceeds tracing, BOS allocation and vesting records, and every related-party or BOS-on-behalf-of-Sovryn payment record
Part II · Staker and lender harm
Sovryn promised protocol-fee revenue to SOV stakers—then removed it from their claim accounting
SOV stakers locked SOV for governance power and protocol-fee revenue intended to align their interests with protecting the protocol. After their shared treasury was stolen, a Tyrone-linked deployment workflow shut live fee claims sixteen days after Sovryn’s January solicitation. In February, the Exchequer multisig replaced the contract code and stole their rights to all newly recorded RBTC and ZUSD fees before any Bitocracy vote.
2955fb83…457755e4.Why this is evidence of deceptive solicitation and SOV-staker damage
The advertisement used a present-tense instruction to enter the staking proposition: lock SOV now and receive Bitcoin and dollar-denominated revenue. Sovryn’s product page (opens in a new tab) , earn page (opens in a new tab) , and staking article (opens in a new tab) repeated the same economic promise.
Sovryn publicly identified Yago as project lead. He designed and joined the small Exchequer framework, announced the revenue redirection documented here as theft, repeatedly described what “we” decided, defended executive action before a vote, and sponsored its later ratification. The official advertisement and the later theft therefore belong to the same leadership and policy record.
Yago personally promoted the same staking logic. In December 2024 he wrote that SOV paid yield from protocol revenue “primarily in the form of BTC” and that making returns more obvious would increase staking desirability. At 13:58 UTC on 17 February 2026—twelve minutes before the pause announcement—he wrote that staking should remain “compelling long-term” and that staker distributions should come from “real revenue.” Read the 2024 statement (opens in a new tab) · read the 17 February statement (opens in a new tab) .
- Solicitation: Sovryn told readers to stake immediately for up to 21.37% APR in BTC and USD.
- Undisclosed live intervention: FeeSharing deployment and Exchequer-submission wallet
0xfee171…4a9e7e · 0xfee171…4a9e7enamed as sender in Tyrone Johnson’s official deployment record deployed code that disabled fee claims; enough owners of the Exchequer multisig0x924f · 0x924f5a…2dc711activated it that day. - Leadership announcement: Yago announced the pause and the revenue redirection documented here as theft after the operational path had already been used on mainnet.
- Staking-revenue theft executed: the Exchequer multisig activated the replacement code. The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e then added RBTC and ZUSD to the 100%-withholding list by 11:44:51. Tyrone’s official deployment record names this wallet as its sender. The vote came later.
The same promise remained live after the staking-revenue theft
Captured on 20 August 2026—nearly six months after the Exchequer multisig activated 100% withholding—the official staking page still said “up to 20% APR,” “rewards you in BTC,” and “PAYOUTS IN BTC,” beside a “BUY SOV” action. The archived HTML begins with Webflow metadata reading “Last Published: 9 February 2026,” after the January claim shutdown and before Yago’s 17 February notice.
3e9cba85…25a33a0.
40740fde…37d8c6.Current mismatch: the official page continued soliciting staking with BTC-return language while the active contract routed listed RBTC and ZUSD fees away from staker claim accounting. This continued publication is direct evidence for the deception, materiality, reliance, and damages inquiry.
Representation and inducement
The official account told readers to “Stake SOV right now” for BTC and USD returns. Yago had already described BTC revenue as the basis of SOV yield and as something that made staking desirable.
Capital committed while the message was live
Between the 12 January promotion and Yago’s 17 February notice, 15 beneficiary wallets directly staked approximately 111,068 SOV. 20 wallets extended locks covering approximately 9,962,956 SOV. The extension total measures already-locked positions, not new purchases.
Knowledge, control, and omission
The Exchequer multisig used its retained power to stop claims on live mainnet on 28 January. Yago later said “we” had decided on the revenue redirection documented here as theft and defended executive action before a vote. The promotion and official staking pages did not explain this retained control, and the staking page continued advertising BTC payouts after 100% withholding went live.
SOV-staker loss files
The replacement code stole stakers’ rights to approximately 0.2912 RBTC and 12,215 ZUSD by excluding those fees from claim accounting as of the 18 August snapshot. Each victim file should connect the dated representation to purchases, staking or lock extensions, fees received, remaining holdings, and realized or continuing loss.
What the contract record shows: measured at Rootstock block 9,162,805 on 18 August 2026, both administrative-owner checks still pointed to the Exchequer multisig 0x924f · 0x924f5a…2dc711 . The totals from 90 RBTC and 46 ZUSD fee events exactly matched the contract’s internal accounting records; no withdrawal event was recorded.
Yago’s public explanation
“The answer is very simple. It’s because it happened. So we don’t know in advance what is going to happen… Now that it has happened, we’re taking action again.”
Community Call #72, answering why the Bitcoin decline caused the response.
The earlier action and price record
The live claim shutdown was deployed on 28 January at 15:29 UTC and activated at 17:51 UTC. Coinbase candles place BTC near $89,139 at deployment and $90,350 at activation. The larger daily decline followed: the 28 January close was about $89,162; the 29 January close was about $84,513, down 5.2%. Inspect the daily candles (opens in a new tab) .
The 29 January fall could not have first triggered the 28 January action. The same retained administrative route had already been prepared and used to stop claims on live mainnet. Yago later cited the recent BTC decline when justifying the February change that stole staker fee rights. Inspect the Coinbase interval (opens in a new tab) · inspect Tyrone’s January code record (opens in a new tab) .
Complete question and answer on the treasury reaction, BTC exposure, and replenishment
Watch the full Community Call #72 on YouTube (opens in a new tab) · source recording and captions checked
Yago’s later position
Yago later said FeeSharingCollector had never been—and was never intended to be—controlled by Bitocracy. Read Yago’s FeeSharing response · 8 March 2026 (opens in a new tab) .
Earlier governance expectation and actual power
SIP-0046 stated that FeeSharingProxy was an exception to Exchequer ownership (opens in a new tab) . Chain history shows both administrative roles for the live FeeSharing contract transferred to the Exchequer multisig in October 2021 and remained there through the February theft.
Code and deployment
Tyrone Johnson authored the January shutdown and February withholding code. His official deployment commit records FeeSharing deployment and Exchequer-submission wallet 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record as sender. That wallet submitted the Exchequer multisig code replacement 51 seconds later and the RBTC/ZUSD operations during the next 2m25s. Inspect the official deployment record (opens in a new tab) .
Execution
Enough owners of the Exchequer multisig approved the replacement code. It went live on 25 February; RBTC and ZUSD were placed on the 100%-withholding list. No prior Bitocracy proposal was located.
Measured staking revenue stolen from staker claim accounting
The code excluded approximately 0.2912 RBTC and 12,215 ZUSD from the accounting entries that let stakers claim fees. Those amounts remained under an Exchequer-controlled withdrawal function.
How this record supports a fraud referral and SOV-staker damages
The official solicitation, undisclosed retained control, pre-announcement mainnet intervention, Yago’s announcement, defense, and ratification sponsorship, continuing post-theft marketing, and measurable theft of fee rights form a documented deceptive-inducement record. Each affected SOV staker’s loss schedule should connect the public evidence above to:
- SOV purchase transactions, dates, quantities, and prices
- Staking transactions, lock duration, expected fees, and actual fees received
- The advertisement or revenue statement the staker saw and when they relied on it
- Unstaking or sale transactions, current holdings, and the method used to value the loss
- Messages, call recordings, or forum posts showing what leadership knew and when
- Internal campaign approval, FeeSharing planning, Exchequer multisig instructions, and analytics showing who targeted or viewed the promotion
Submit purchase, staking, reliance, and loss records through the encrypted evidence intake.
FeeSharing transaction ledger · 15 entries
| UTC / block | What happened | Transaction |
|---|---|---|
#3,769,580 | The contract was created with the deployer holding both administrative roles | 0x92560ba4…245e5e (opens in a new tab) |
#3,769,600 | First owner role transferred to Exchequer | 0xdb6f399d…dc1d26 (opens in a new tab) |
#3,769,602 | Second owner role transferred to Exchequer | 0xd095df4d…4c3312 (opens in a new tab) |
#8,469,257 | The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e deployed code that disabled staker fee claims | 0x6fa7f9ca…f306a7 (opens in a new tab) |
#8,469,265 | The 0xfEE171…4a9e7e deployment wallet submitted the claim-shutdown request as Exchequer multisig transaction 2166 | 0x0fd70e59…22be1a (opens in a new tab) |
#8,469,615 | Enough Exchequer multisig owners approved and activated the claim shutdown | 0xedc2cf4b…d93e96 (opens in a new tab) |
#8,475,868 | The 0xfEE171…4a9e7e deployment wallet submitted Exchequer multisig transaction 2167 to restore the earlier code | 0xec720d14…d1d071 (opens in a new tab) |
#8,475,916 | Enough Exchequer multisig owners approved and restored claims after 44h20m01s | 0x1ba84692…52a33b (opens in a new tab) |
#8,544,919 | The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e deployed the 100%-withholding code | 0x6b281895…696e96 (opens in a new tab) |
#8,544,922 | The 0xfEE171…4a9e7e deployment wallet submitted the code replacement as Exchequer multisig transaction 2196 | 0x9c78c855…9a947b (opens in a new tab) |
#8,544,924 | The 0xfEE171…4a9e7e deployment wallet submitted 100% RBTC withholding as Exchequer multisig transaction 2197 | 0x4d9d1306…162601 (opens in a new tab) |
#8,544,926 | The 0xfEE171…4a9e7e deployment wallet submitted 100% ZUSD withholding as Exchequer multisig transaction 2198 | 0x01c6a7b8…a7c431 (opens in a new tab) |
#8,565,302 | Enough Exchequer multisig owners approved and activated the replacement code | 0x1c8293f9…481c60 (opens in a new tab) |
#8,565,356 | The 0xfEE171…4a9e7e deployment wallet executed the RBTC 100%-withholding addition | 0x994d2cac…04d8ba (opens in a new tab) |
#8,565,358 | The 0xfEE171…4a9e7e deployment wallet executed the ZUSD 100%-withholding addition | 0x33b47515…fe1138 (opens in a new tab) |
Loans and lender harm
Linked wallets repeatedly drew RBTC and left SOV collateral to settle the debt
The mechanism spans the project’s history. In 2021, the Exchequer and one of its owner-addresses drew 34.5001 RBTC against approximately 259,930 SOV and placed every RBTC into FastBTC’s user-payout reserve. No principal was retired through borrower-funded repayment; liquidators and collateral swaps satisfied the debt. More than four years later, the same 4f39 address joined three other B7-linked wallets in the coordinated February 2026 borrowing session. A separate 2022 margin position created lender exposure without paying RBTC to its wallet and now dominates the modeled shortfall.
This happened before: treasury SOV financed FastBTC liquidity and was left to liquidation
Four direct iWRBTC borrows · 7 October–8 November 2021 · 34.5001 RBTC loaded into FastBTC · zero borrower-funded repayment
More than four years before the February 2026 session, the Exchequer and then-registered Exchequer owner-address and later February 2026 borrower 4f39 · 0x4f3948…ae2e97 used the same iWRBTC lending pool to obtain RBTC against SOV. The Exchequer had sent 50,000 SOV to 4f39 (opens in a new tab) six days before its 5-RBTC opening; balance conservation proves that at least 16,037 SOV of that opening’s collateral derived from the receipt. Immediately after the opening, the Exchequer transferred another 120,000 SOV (opens in a new tab) to 4f39 in the next transaction of the same block; 4f39 later drew another 9.5 RBTC. On 8 November, the SOV stakers’ shared treasury multisig Exchequer · 0x924f5a…2dc711 itself opened positions paying 0.0001 and 20 RBTC. Together the four calls paid out 34.5001 RBTC.
Those transfers funded FastBTC; they were not RBTC routed out through the bridge. The first two were plain native transfers with empty calldata. The other two opening calls paid the production wallet directly. In every case, FastBTC’s 2021 production RBTC reserve 0xca1c…147f · 0xca1c5b…6f147f increased by the exact payout amount at that block. FastBTC’s own relay code (opens in a new tab) describes the opposite direction: after detecting a user’s Bitcoin deposit, an administrator paid RBTC from this wallet to the user. The deployed wallet source (opens in a new tab) had no Bitcoin destination, peg-out request, or deposit event—only a payable receiver and owner/admin withdrawals. After the 5-RBTC top-up, FastBTC admin payouts exceeded 5 RBTC within 2h51m58s and the reserve fell below its pre-top-up balance, proving the increment was used as payout liquidity.
None of the four positions recorded added collateral or a borrower-funded CloseWithDeposit repayment. Instead, 62 liquidations and two final collateral swaps satisfied the debt from pledged SOV; liquidators seized approximately 257,808 SOV. The mechanism converted SOV collateral into operational RBTC without an immediate open-market SOV sale: iWRBTC lenders supplied the RBTC, FastBTC received the liquidity, and the pledged SOV later settled the debt.
The concentration was by value, not by loan count. Across all 198 historical and active SOV-backed direct iWRBTC Borrow positions in the audit, these four positions and the four February 2026 B7-linked positions were only 8 loans, yet accounted for 84.1% of opening WRBTC principal and 97.8% of opening SOV collateral. Within the closed positions that underwent liquidation with no deposit repayment, the four 2021 positions represented 93.2% of opening WRBTC principal—4 of 29 positions.
SIP-0012’s public proposal (opens in a new tab) identified 100 BTC from the Origin BTC multisig as the proposed source for FastBTC liquidity. It did not disclose SOV-backed lending as a financing method. The missing record is whether these loans supplemented or replaced that allocation, who authorized and accounted for them, where FastBTC recorded the matching Bitcoin-side value, and how the seized SOV and resulting treasury interest were disclosed to SOV stakers.
- FastBTC reserve funded
- 34.5001 RBTC
- SOV pledged
- ≈259,930 SOV
- SOV liquidated
- ≈257,808 SOV
- Borrower repayment
- 0 WRBTC
- All direct-Borrow share
- 84.1% by opening WRBTC
- Closed liquidation share
- 93.2% by opening WRBTC
Four openings, one liquidity wallet, one repayment path
Every payout increased the published FastBTC production reserve by the exact amount. Exact adjacent-block balances and hashes are preserved in the evidence packet.
| Opening | Borrower | Payout / SOV pledged | FastBTC reserve proof | Resolution |
|---|---|---|---|---|
#3,748,299 0x44154829…1fbd29 (opens in a new tab) | B7-first-funded wallet; Exchequer owner-address from 2021 to 2023; later February 2026 borrower 4f39 · 0x4f3948…ae2e97 0x9f93b2f6…f759f8 | 5 RBTC ≈23,051 SOV | Forwarded after 3m 10s Reserve +5 RBTC 0x6d64f636…d8e562 (opens in a new tab) | 24 liquidations Final collateral swap |
#3,825,333 0x4a0457f0…f6460a (opens in a new tab) | B7-first-funded wallet; Exchequer owner-address from 2021 to 2023; later February 2026 borrower 4f39 · 0x4f3948…ae2e97 0xb28065c0…b9808b | 9.5 RBTC ≈77,174 SOV | Forwarded after 2m 42s Reserve +9.5 RBTC 0x95072091…482b4c (opens in a new tab) | 25 liquidations Fully resolved by liquidation |
#3,832,154 0xa9b1a043…005728 (opens in a new tab) | Sovryn Exchequer multisig Exchequer · 0x924f5a…2dc711 0x86bf4ebc…b8dcd8 | 0.0001 RBTC ≈1 SOV | Direct in opening call Reserve +0.0001 RBTC 0xa9b1a043…005728 (opens in a new tab) | 3 liquidations Final collateral swap |
#3,832,262 0x6ebd5b2d…4e9b35 (opens in a new tab) | Sovryn Exchequer multisig Exchequer · 0x924f5a…2dc711 0x55c584af…0ef672 | 20 RBTC ≈159,704 SOV | Direct in opening call Reserve +20 RBTC 0x6ebd5b2d…4e9b35 (opens in a new tab) | 10 liquidations Fully resolved by liquidation |
Dossier conclusion The complete lifecycle and the same 4f39 address’s reappearance in 2026 support the conclusion that collateral liquidation was the chosen repayment path: obtain RBTC without an immediate open-market SOV sale, make no borrower-funded repayment, and leave pledged SOV to satisfy the debt. The authorizations, key instructions, FastBTC Bitcoin and Rootstock ledgers, provider agreements, reserve-rebalancing records, and treasury accounting should identify the responsible decision-makers and the beneficial owner of the corresponding value.
Four-loan outcome snapshot: Rootstock block 9,158,536 · 17 Aug 2026 07:23:15 UTC. The separate all-eleven model for the iWRBTC lending pool is pinned to block 9,162,594.
The coordinated February loan sequence
Seven B7-first-funded wallets withdrew more than 10 million SOV; four opened SOV-backed loans, and Yago’s staking-revenue announcement followed the final opening by 12h35m18s.
- Seven linked wallets withdrew approximately 10,048,901 SOVFour acted inside 7m13s. Three more followed 1h38m later; the first three transactions in the opening group used the same gas price and gas limit.
- Four of those wallets opened loans inside 15m12sEach borrower had withdrawn matured stake 186–7,083 seconds earlier. The borrow calls supplied approximately 7,006,709 SOV, and the borrowers received 1.465 RBTC net.
- Yago announced the staking-revenue change The reward pause and the change documented here as theft (opens in a new tab) followed the fourth loan opening by 12h35m18s.
- Linked wallets rebuilt long-duration stakes togetherThree non-borrowers restaked the exact amounts they had withdrawn. With three other linked wallets, approximately 6,986,587 SOV entered stakes inside 43m16s; five used the same 16 February 2029 lock target.
Dossier conclusion The withdrawals, loan openings, reward announcement, exact-value restakes, shared lock targets, and repeated prior sessions establish a coordinated sequence supporting investigation of advance knowledge and conflicts. Custody, instruction, and internal planning records can allocate the people directing it.
8 March 2026
Public notice
Warning and evidence delivered
Public Disclosure #2 (opens in a new tab) listed the four borrow transactions, tied their timing to the reward announcement, warned that illiquid collateral endangered RBTC lenders, asked Yago and Nahari to close the loans immediately, and requested stronger collateral rules.
- Power to act
- Leadership could call for repayment, initiate an independent risk investigation, support a pause or rule change, disclose control and conflicts, or back the requested governance remedy.
- Recorded response
- On Call #73 Yago disclaimed relevance and said SOV owners could do what they chose.
- Omitted
- No commitment to close the loans, require repayment, pause exposure, investigate coordination, or protect existing RBTC lenders.
- Protective action not taken
- The four loans remained open; no later collateral deposit occurred.
- Later on-chain outcome
- Nine August liquidations seized approximately 1.57M SOV; all four positions remained active and unsafe with approximately 1.1151 WRBTC outstanding.
- Why the dossier infers intent
- Specific notice, ability to mitigate, dismissal, continued inaction, and the later predicted harm support an inference of knowing disregard.
- Records to compel
- Borrower-key custody, internal notice, risk review, repayment instructions, and all communications from 17 February through the August liquidations.
- Later confirmation
- Disclosure #4 (opens in a new tab) documented liquidation and the continuing pool impairment.
Yago responds when the founding-member loan is raised
Excerpt checked against the full call
“No, of course not. What’s it got to do with me? Or the conversation that we’re having? Like, people who own SOV can do with it whatever they choose.”
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
57:40–58:40 follow-up
The question explicitly stated Sovryn’s responsibility to protect RBTC lenders from losses caused by illiquid collateral.
What the answer did
Yago shifted the remedy toward future collateral-rule changes. He supplied no commitment to close the identified loans, require repayment, pause the risk, disclose conflicts, or begin an independent investigation.
Follow-up states the duty to protect RBTC lenders from illiquid collateral
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
Loan transaction ledger · 4 openings and 9 liquidations
| UTC / block | Borrower / loan | Principal | Collateral | Transaction |
|---|---|---|---|---|
#8536319 | 0x91ab7f…021684 0xeb0bb06d…949ebf | ≈0.3862 WRBTC | ≈1,839,490 SOV | 0xb55fb894…fcc815 (opens in a new tab) |
#8536335 | 0x4f3948…ae2e97 0x39519639…6553b0 | ≈0.4614 WRBTC | ≈2,198,044 SOV | 0x1082b3e0…7b865d (opens in a new tab) |
#8536347 | 0xb493b1…a2c155 0xa499ced3…f8d45a | ≈0.317 WRBTC | ≈1,510,060 SOV | 0x6b7ddf65…8a8489 (opens in a new tab) |
#8536354 | 0x50110e…f07962 0xbecb523d…83b474 | ≈0.305 WRBTC | ≈1,452,809 SOV | 0xc0c07f1a…c86074 (opens in a new tab) |
| UTC / block | Loan | WRBTC repaid | SOV seized | Transaction |
|---|---|---|---|---|
#9155133 | 0xa499ced3…f8d45a | ≈0.1065 | ≈454,473 | 0x34fb3757…937f3a (opens in a new tab) |
#9155138 | 0xbecb523d…83b474 | ≈0.012 | ≈51,401 | 0x0a09be12…bbb233 (opens in a new tab) |
#9155151 | 0x39519639…6553b0 | ≈0.009 | ≈38,491 | 0x00b1c903…942ac6 (opens in a new tab) |
#9155159 | 0x39519639…6553b0 | ≈0.127 | ≈544,045 | 0x79183dc6…54159f (opens in a new tab) |
#9155187 | 0x39519639…6553b0 | ≈0.05 | ≈239,260 | 0x2036ecac…caae8a (opens in a new tab) |
#9155488 | 0xa499ced3…f8d45a | ≈0.02 | ≈97,573 | 0xb9c886a0…d918d3 (opens in a new tab) |
#9155501 | 0x39519639…6553b0 | ≈0.01 | ≈48,590 | 0x62e701a2…c5cb23 (opens in a new tab) |
#9155516 | 0x39519639…6553b0 | ≈0.01 | ≈48,590 | 0x4732cf0e…f3cb66 (opens in a new tab) |
#9155548 | 0xa499ced3…f8d45a | ≈0.01 | ≈48,786 | 0x4112e7d0…05d28b (opens in a new tab) |
A separate 2022 leveraged SOV position became the largest shortfall
Opened by marginTrade on 3 February 2022 · no RBTC paid to the borrower wallet · active and unsafe at the pinned 18 August 2026 snapshot
2022 leveraged-position borrower 8D51 · 0x8d5158…be0fb7 opened this position (opens in a new tab) through a marginTrade, not a direct Borrow. The transaction created approximately 5.637 WRBTC of protocol debt, but no RBTC was paid to 8D51; the borrowed value remained inside Sovryn and was swapped into additional SOV, producing approximately 96,174 SOV of opening collateral. It was a leveraged long-SOV position, not a direct RBTC withdrawal.
After later collateral additions and 16 liquidations, the position still owed approximately 3.6666 WRBTC. The same wallet was first funded by B7 in the uninterrupted setup sequence that included all four 2026 borrowers. In June 2022, later February borrower and former Exchequer multisig owner 4f39 · 0x4f3948…ae2e97 sent it approximately 385,915 SOV; within 4m57s, 8D51 allocated the exact amount across three loan positions.
Exact SOV handoff (opens in a new tab) · First redeposit (opens in a new tab) · Second redeposit (opens in a new tab) · Third redeposit (opens in a new tab)
- Current principal
- ≈3.6666 WRBTC
- SOV collateral
- ≈613,652 SOV
- Standalone AMM value
- ≈0.1107 WRBTC
- Modeled shortfall
- ≈3.5559 WRBTC
- Modeled coverage
- ≈3%
Dossier conclusion This position establishes long-running B7-linked lender exposure and dominates the current modeled shortfall. It is not included among the direct RBTC withdrawals or the historical Borrow concentration above. Yago’s documented leadership, policy, response, and ratification roles place the continuing exposure within his accountability record; custody and instruction records can allocate the executing key.
Yago dismissed the connection while leaving the transactions unchallenged
When the SOV-backed loan was raised, Yago answered, “No, of course not. What’s it got to do with me?” and said SOV owners could do what they chose. He later called the loan link baseless and characterized the broader exchange as “conspiratorial thinking” and “noise.” The preserved exchange contains no public commitment to require repayment, pause affected lending, pursue any available protective action, or investigate the identified positions.
Complete question and answer containing the baseless, conspiratorial, and noise response
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
Borrower-cluster value reached Sovryn’s USDt0 campaign signer
The loan record establishes the lender exposure. This separate trail follows where borrower value later reconverged: balances moved into February borrower and later RBTC hub b493 · 0xb493b1…a2c155 , that hub paid USDt0 campaign signer de169 · 0xde1690…5f6af2 current registered owner-address of the 0x924f Exchequer multisig, which also guards both Governors , and the campaign-signer wallet later sent the identified swap transaction and funded Sovryn’s USDt0 campaign.
- Borrower balances came back together. On 18 June, February borrower
91AB · 0x91ab7f…021684and February borrower5011 · 0x50110e…f07962moved nearly all of their 0.3943 and 0.4129 RBTC balances to February borrower and later RBTC hubb493 · 0xb493b1…a2c155. February borrower4f39 · 0x4f3948…ae2e97sent 0.705 RBTC to a separate hub. - Cluster hub to campaign signer. On 7 July, February borrower and later RBTC hub
b493 · 0xb493b1…a2c155sent 0.236 RBTC to USDt0 campaign signerde169 · 0xde1690…5f6af2current registered owner-address of the 0x924f Exchequer multisig, which also guards both Governor contracts . Inspect the transfer (opens in a new tab) . - Identified swap transaction and campaign funding. On 13 July, USDt0 campaign signer
de169 · 0xde1690…5f6af2sent approximately 0.234 RBTC in the transaction identified in the transaction audit as the RBTC-to-USDt0 swap. About two hours later the same wallet signed a Merkl reward-campaign transaction funding approximately 14,417 USDt0. Obtain the swap receipt/output and account ledger to complete the conversion accounting. Inspect the identified transaction (opens in a new tab) · inspect the campaign transaction (opens in a new tab) . - Merkl’s campaign page connects the funding to Sovryn’s live product. The official opportunity page (opens in a new tab) names the protocol as Sovryn, the chain as Rootstock, a 50/50 RBTC/USDT0 liquidity position, and an approximately 14,000-USDt0 reward pool. Its Deposit action links directly to the Sovryn market-making dapp (opens in a new tab) . The displayed campaign runs from 16 July through 14 September 2026.
- Displayed promotion followed. Three days later, an account displayed as FrenchVictory announced a 10% APR USDt0/RBTC migration campaign to the Sovryn community.
Borrower-cluster value reached the USDt0 campaign-signer wallet at 0xde169…, a current registered owner-address of the operational 0x924f Exchequer multisig that also guards both Sovryn Governor contracts. That same wallet sent the transaction identified as the swap and funded the approximately 14,417-USDt0 Sovryn campaign. The swap output, account ledger, and campaign authorization are the next records needed to complete the accounting trail.
9447bcb8…00dc28a. The supplied image contains no native platform metadata; the displayed date should be verified from the platform record.What RBTC lenders stand to lose
| Measure | RBTC | Meaning |
|---|---|---|
| Total lender claims | ≈29.2089 | Canonical accounting claim balance at the block |
| Pool cash | ≈21.4134 | Immediately available before redemptions |
| SOV-backed principal | ≈4.7848 | All eleven active SOV-backed positions; all unsafe |
| Estimated recovery from the identified SOV/WRBTC exchange pool | ≈0.7408 | Estimated proceeds if all SOV collateral were sold through that one reserve pool at once |
| Estimated pool-wide shortfall | ≈4.0441 | 13.8% of lender claims, assuming no borrower repayment, new capital, or outside liquidity |
| Late-lender stress recovery | ≈3.0107 | Against approximately 7.7956 RBTC remaining after cash exhaustion |
Outstanding lender exposure. The pool-wide collateral-sale estimate measures a 13.8% shortfall across all lender claims. A separate cash-exhaustion stress case measures a 61.4% loss for lenders left after earlier withdrawals consume the available RBTC, assuming zero SOV recovery and no repayment, new capital, insurance, or rescue. The located public record contains no committed cure.
Notice and response
Users warned leadership. Protection did not follow.
Victims supplied transaction hashes, balances, risk mechanics, and concrete requests. Leadership had the power to disclose, investigate, restore, pause, or support recovery. The public record shows no resulting protective commitment; liquidations and impairment followed.
The notice record joins knowledge to consequence: exact warnings were delivered, the identified routes and loans remained unresolved, and linked voting defeated the executable FeeSharing recovery.
Inspect the complete notice, response, and recovery record
8–28 March
Treasury notices
The RBTC route and total-asset warning
- Warning delivered
- Disclosures #1 and #3 published the route, balances, explorer links, and the FastBTC/Exchequer accounting conflict.
- Power to act
- Leadership and Exchequer principals could publish the ledger, freeze further destinations, disclose the counterparty, and preserve signer records.
- Recorded response
- Yago called it overall treasury consolidation; Nahari invoked a third-party FastBTC liability.
- Missing support
- No transaction mapping or liability support was supplied. FastBTC’s 25.66001145-BTC shutdown inventory and the later 23.1464-RBTC Exchequer route are separate episodes that reached the same terminal address.
- Protection not taken
- No public exchange-account preservation, independent reconciliation, or complete current treasury statement followed.
- Continuing harm
- Victims lack a verified ledger and proceeds map; practical Exchequer liquidity remained impaired.
- Intent inference
- Organizational acknowledgment plus unsupported accounting after precise notice supports an inference of insider-directed execution.
- Records to compel
- Exchange customer-identification and account records, Exchequer instructions, FastBTC contracts, ledger, invoices, DD payees, and proceeds tracing.
March–April
Fee recovery
An unopposed signal that expired, a defeated remedy, then ratification
- Warning delivered
- The SIP-0088 signal received approximately 50,211,182 votes for and zero against, but its recorded state was Expired; it was not executed.
- Power to act
- Exchequer could restore the previous FeeSharing code and transfer administrative control; leadership could support the proposals that would make those changes.
- Recorded response
- Five B7-first-funded wallets supplied every vote against both executable proposals.
- What followed
- The final recovery was blocked despite the earlier unopposed signal and later claim of Bitocracy legitimacy.
- Protection not taken
- The contract code that began withholding fees before the vote remained in place.
- Continuing harm
- The contract still omits listed-token revenue from the accounting entries that let stakers claim fees; the Exchequer multisig retains withdrawal authority.
- Intent inference
- Outcome-determinative linked voting followed by retrospective ratification supports deliberate preservation of the disputed change.
- Records to compel
- Stake custody, delegation history at vote snapshots, voting instructions, and internal SIP-0088/0089 communications.
Part III · Blocked recovery
Recovery was blocked—and the taking was ratified later
Five B7-first-funded wallets cast every vote against two executable recovery proposals. Later, B7-origin stake supplied 99.32% of the affirmative vote for Yago’s retrospective ratification through one operational voter address.
Proposal record: SIP-0085 was created on 6 December 2024. The non-executing SIP-0088 support vote was created on 5 March 2026; the two proposals that could restore the fee contract followed on 20 March. Yago published the SIP-0089 ratification proposal on 23 March; GovernorAdmin proposal 26 was created on-chain on 17 April. Exact contract names, proposal numbers, blocks, and times are in the public packet.
SIP-0085
The BOS distribution proposal received 23.448 million votes for and 13.437 million against: 63.57% support, below the required greater-than-70%. Enough votes participated for the result to count. Without the B7-linked votes on either side, support would have been 94.95% and participation would still have remained high enough. The linked bloc changed the result.
Read the SIP-0085 forum record (opens in a new tab) · Read Sovryn’s voting rules (opens in a new tab)
SIP-0088
Five B7-first-funded wallets supplied 100% of the approximately 62,572,734 votes against each paired executable recovery proposal—about 53.5% of all votes cast and enough to determine defeat.
SIP-0089
Yago sponsored retrospective ratification. One day before the proposal, two direct B7-first-funded addresses— A738 and 9369 —delegated their voting power to 0xfEE171…4a9e7e . That address was itself first funded through B7-linked C0AA. It is the FeeSharing deployment wallet named in Tyrone Johnson’s official deployment record, an Exchequer signer, and the SIP-0089 proposer-voter. At the vote snapshot, the two delegated weights summed exactly to the 31,574,812.5 votes it cast for ratification.
- 99.32%B7-origin affirmative voting power
- 31,574,812.5 of 31,791,028.47 votes for
- 0.68%All other affirmative voting power
- 216,215.97 votes for, combined
What this establishes: B7-origin stake supplied 99.32% of the affirmative vote; every non-B7 source combined supplied 0.68%. The vote demonstrates near-total control of the ratification’s supporting weight through one operational voter address. Public records place Yago in sponsorship and leadership, while custody and instruction records remain necessary to allocate the private keys to specific natural persons.
A738 delegation (opens in a new tab) · 9369 delegation (opens in a new tab) · 31,574,812.5-vote transaction (opens in a new tab) · Yago’s forum proposal (opens in a new tab)
The dossier concludes that governance was not a neutral check on the disputed conduct. B7-first-funded wallets supplied every vote against executable recovery, then B7-origin stake supplied 99.32% of the affirmative weight for ratification through one operational voter address after the withholding code was already live.
Intent finding
A connected pattern of control, execution, notice, and harm
Intent is inferred from the sequence and convergence of the documented acts.
Inspect the eight facts supporting the intent finding
- Advance controlRetained owner powers, concentrated signers, B7 funding, and threshold-capable Guardian paths existed before the disputed acts.
- Undisclosed executionUsable reserves were stolen through repeated transfers; code that stole staker revenue rights went live before a governance vote.
- Coordinated timingFour linked loans opened within 15m12s, hours before Yago’s reward announcement.
- Specific public noticeVictims supplied transactions, balances, risk mechanics, named requests, and a recovery proposal.
- Dismissal and unsupported accountResponses denied relevance, attacked the inquiry, or invoked a liability without ledger support.
- Ability to mitigateLeadership, Exchequer, and governance principals had practical routes to pause, repay, restore, disclose, and investigate.
- No recorded mitigation and concentrated votingNo recorded protective commitment followed; linked voting defeated the executable recovery.
- Measurable later harmLiquidations, unsafe positions, stolen staker fee rights, stolen usable treasury assets, and an unreconciled proceeds map remained.
The combined warning, dismissal, absence of a recorded mitigation commitment, later liquidations, and impairment support the dossier’s inference of knowing disregard for lender harm. Integrated with the treasury and governance record, the dossier concludes that the course was intentional and insider-directed.
Responsibility
Who did what
Public records establish the policy, finance, and implementation roles. Key-custody and instruction records can allocate each private execution.
The leadership-to-execution chain
- 1Yago announced, justified, and sought to ratify the policy. Sovryn called him project lead (opens in a new tab) . He designed the small Exchequer framework, proposed himself as a member, announced “what we have decided” (opens in a new tab) , said the decision came before Bitocracy ratification (opens in a new tab) , and described his later proposal as ratifying it (opens in a new tab) .
- 2Tyrone authored and committed the code and deployment record. That official record names 0xfEE171…4a9e7e as sender; the wallet then deployed the FeeSharing replacement and submitted the Exchequer multisig actions on-chain.
- 3Nahari occupied the finance lane. His records cover Exchequer participation, budgets, financial reporting, and the FastBTC treasury explanation.
The sequence joins policy, implementation, and finance; custody and communications remain necessary to allocate private execution.
Published role-wallet anchors: SIP-0041 published Exchequer Committee wallet Yago role wallet · 0x428a80…bdb2be · SIP-0041 published Exchequer Committee wallet linked in the Nahari record Armando role wallet · 0xa6df7b…63f4b7 · SIP-0047 published Contracts Guardian wallet Tyrone role wallet · 0x27ae0f…1346b7
Edan “Yago” Yago
Photograph source: CoinDesk Consensus Hong Kong 2025 speaker profile (opens in a new tab)
- Directly attributable
- Project-lead role; authorship of the approved Exchequer framework; Exchequer participation; 17 February reward pause/redirection announcement; Call #72 consolidation explanation; Call #73 responses; executive-before-ratification account; and retrospective-ratification sponsorship.
- Dossier conclusion
- Yago was the leadership, policy, management, public-explanation, dismissal, and ratification principal for the disputed sequence.
- Compel
- Instructions, board/leadership communications, borrower-key allocation, exchange account records, and knowledge of the loan timing.
Elan Nahari / “Armando Munoz”
Photograph source: Real-World Asset Summit 2025 speaker profile (opens in a new tab)
- Public Sovryn identity
- Nahari used “Armando Munoz,” shortened to “Armando” in project accounts and records.
- Directly attributable
- Co-founder and core-contributor roles; participation with Yago in the Exchequer’s executive treasury process; budget and financial-report work; first-person forum posts; and the Call #73 FastBTC account. At least eight linked files display elan@remake.money.
- Dossier conclusion
- The documentary chain places Nahari in Sovryn’s treasury accounting, reporting, budget, and explanation lane alongside Yago’s executive leadership.
- Compel
- Native account-authentication and custody records, report workpapers, general ledger, FastBTC agreements, signer instructions, and related-party records.
“Tyrone Johnson”
- Public Sovryn identity
- The pseudonym used in project, governance, source-code, and account records.
- Documented role and actions
- Publicly identified technical team lead; authored and merged the shutdown and withholding code; authored and committed the official mainnet deployment record whose artifact names FeeSharing deployment and Exchequer-submission wallet
0xfee171…4a9e7e · 0xfee171…4a9e7enamed as sender in Tyrone Johnson’s official deployment record ; published role wallet later sent and signed a Guardian rotation; an account displayed as Tyrone supplied conversion and bridge wallet8C · 0x8c9143…84f50bsupplied by the displayed Tyrone project account during the on-chain-matched May 2024 session . - Dossier conclusion
- The public Tyrone account is the documented technical and operational implementer or facilitator for core elements of the course.
- Compel
- Native Discord records, deployment logs, device/key custody, 8C continuity, DD signer identities, and the instruction chain for code and operations.
Combined responsibility finding: the transaction history establishes a centrally directed B7 operation. Yago, Nahari, and Tyrone occupy the documented leadership, accounting, and implementation chain around that conduct. Authorities should compel the custody, instruction, and communication records that assign the B7 funding wallet, borrower wallets, conversion and bridge wallet 8C, destination shared wallets DD, Exchequer multisig, and exchange actions within that chain.
The supplied 8C operational screenshots
These images show why 8C appears in the attribution record. They are displayed as context, while the transaction match—not the screenshot alone—carries the corroboration.
8C · 0x8c9143…84f50b supplied by the displayed Tyrone project account during this on-chain-matched May 2024 session and describes the same bridge and negligible-balance retry pattern independently visible on-chain. SHA-256 e9628ae8…e6a3b63. The platform’s original export and account-access record should be preserved.Part IV · Sovryn/BOS fund paths
Sovryn and BOS money used the same financial network
The Sovryn estimate above includes the identified Exchequer assets and FastBTC’s four shutdown receipts. BOS proceeds are not added to that figure; this part shows where the projects’ custody, payment, and exchange infrastructure overlapped. On Community Call #73, Yago acknowledged that BOS paid expenses for Sovryn and denied fund mingling nine and a half minutes later.
On two networks, independently reconstructed funds converged at the same off-ramps
On Bitcoin, at least 20.01114355 BTC attributable to a high-confidence BOS Origins collector topology reached bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5 (opens in a new tab) . All three later Exchequer pegout routes delivered 23.13948498 BTC to that exact address.
On Ethereum, BOS sale funds used 0x509201… → 0xe1D4… → 0x5f65…. Exchequer-derived DD funds later reused the exact same forwarding proxy and terminal; another DD route used a sibling proxy from the same deployment family and reached the same terminal.
- Candidate benchmark scale
- $4,169,986.84 · 85.3% of Origins’ USD-valued counter at the matched daily-VWAP benchmark.
- Exact convergence
- One Bitcoin deposit address and one exact Ethereum proxy-to-terminal route were reused across independently reconstructed BOS and Exchequer sources.
- Exchequer stablecoins reaching shared rails
- At least 411,750.640097 nominal stablecoin units reached recurring recipients or the common Gemini-labeled endpoint.
Exact deposit-address reuse is materially stronger than a generic “same exchange” label. It supports a common credited-account, merchant, or off-ramp relationship that the exchange can identify.
Community Call #73 · two statements, 9m 30s apart
Yago said BOS paid Sovryn expenses—then denied fund mingling
At 35:03, Yago said some funds were paid by BOS on Sovryn’s behalf and needed to be consolidated at the end of 2025. At 44:33, the moderator asked whether Sovryn was mingling funds with BOS. Yago answered, “No.” Hear the denial in his own voice beside the earlier statement and the shared-route evidence.
Yago says BOS paid funds on Sovryn’s behalf
Statement checked against the full call
“Some of those funds were paid out by BOS on behalf of Sovryn.”
He continued that those funds needed to be consolidated at the end of 2025 and said delaying consolidation let Sovryn maintain more liquidity in the protocol.
Hear the statement in the full Community Call #73 (opens in a new tab) · full source recording and captions checked
Asked whether Sovryn was mingling funds with BOS, Yago answers no
Excerpt checked against the full call
“No.”
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
The denial does not reconcile with Yago’s own cross-payment admission or the public-chain convergence. The missing records are the authorizations, separate ledger entries, project allocations, reimbursements, credited exchange accounts, and identities behind the shared wallets.
Follow every reconstructed collector, wallet, proxy, recipient, and exchange route
Multichain sale reconstruction
The candidate multichain benchmark reaches 85.3% of Origins’ sale counter
Origins records $4,888,380.30 in its USD-valued usdCollected field. Reconstructed stablecoin receipts and high-confidence Cardano and Bitcoin candidate paths produce a $3,974,628.13–$4,368,551.68 funding-day market benchmark. The daily-VWAP estimate is $4,169,986.84, or 85.3% of that counter.
Direct token paths
$432,623.93 in canonical stablecoins
The expanded reconstruction follows canonical stablecoin receipts on Ethereum, BNB Chain, Polygon, and associated collector branches. It includes the direct collector routes into 0x509201…AbD6 and labeled exchange infrastructure.
High-confidence Origins attribution
2,440,904.338471 ADA · about $1,873,923.65
Three Cardano pools contain 1,834 deposit UTXOs from 1,254 unique deposit addresses. Early pools routed to a Binance-labeled endpoint. The later controller placed an order using 277,394.921276 ADA and 36,652,194.91 BOS; the next transaction increased Minswap reserves by 277,392.171276 ADA and 36,652,194.91 BOS (opens in a new tab) .
High-confidence Origins attribution
20.01527801 BTC · about $1,863,439.26
The clean Bitcoin topology contains 297 one-output sweeps, 927 external input UTXOs, and 699 unique input addresses. Its collector rotation occurred within minutes of the independently reconstructed Cardano rotation before the balance moved to the later Exchequer deposit address.
Measurement basis: canonical stablecoins at face value and ADA/BTC receipts at matched Kraken daily low, VWAP, and high benchmarks. Bitcoin and Cardano are high-confidence Origins/Fireblocks attributions based on sale timing, unique-deposit sweep architecture, collector succession, and synchronized cross-chain rotations. Fireblocks documents the unique-address and sweep architecture (opens in a new tab) ; its vault map and the Origins order export can supply the first-party address assignment.
Central reconciliation difference: approximately $718,393.46. Accepted assets and vaults outside this reconstruction, order-time pricing, refunds, and platform accounting are the records needed to reconcile that difference.
BOS and Exchequer stablecoins reused the same Ethereum deposit route
The January Exchequer route reused the exact forwarding proxy and terminal previously used after BOS collector receipts. The March route used a sibling proxy from the same EIP-1167 deployment family and reached the same terminal.
- BOS collector lot at terminal
- ≥150,463.919739 USDT
- January Exchequer event
- ≥66,644.658655 USDT
- January + March Exchequer routes
- ≥133,809.640217 units
- 1BOS collectors and DDindependent sourcesSale proceeds and Exchequer-derived assets
- 2Same forwarding route
0xe1D4…DCd0Exact proxy reuse; sibling proxy in March - 3Gemini-labeled terminal
0x5f65…e932Credited customer or subaccount unresolved
The BOS route
0x509201 sent 200,000 USDT to the forwarding proxy (opens in a new tab) , which forwarded the exact amount (opens in a new tab) to the terminal. Balance conservation assigns at least 150,463.919739 USDT of that event to the designated collector lot.
The Exchequer routes
On 12 January, DD sent 100,000 USDT to the exact same proxy (opens in a new tab) , which exact-forwarded it to the same terminal (opens in a new tab) . On 30 March, DD sent 120,000 USDT to 0x509201; after a USDT-to-USDC swap, 122,000 USDC entered the sibling proxy (opens in a new tab) and reached the same terminal (opens in a new tab) .
Forwarding family: 0xe1D4…DCd0 , 0xF6c8…933e , and terminal 0x5f65…e932 . Gemini records can map the proxies and terminal to the customer, subaccount, beneficial owner, internal credits, trades, withdrawals, and fiat wires.
Shared custody and recurring payments
One custody and payment network served Sovryn treasury activity and BOS administration
Confirmed Exchequer-derived receipts to DD comprise 522,242.076079 official stablecoins (508,947.877906 USDT and 13,294.198173 USDC), 44.109475650313137836 ETH, and 52.853639178690725711 BNB. The matching DD Safes use the exact five-owner set installed on the official BOS token-owner and allocation Safes, and the same 8C address deployed both families. 0x509201…AbD6 and 0xcD9003…fBAA approved all 14 reviewed Ethereum DD executions.
Custody links
- Deployment8C created DD and the official BOS Safe family
- Shared owner setthe same five addresses control both Safe families
- Observed quorum0x509201 and 0xcD900 approved every reviewed DD execution
Payment metrics
- 277,941 USDT
- DD transfers outside the exchange routes
- 24 recipients
- every address also paid by 0x509201
- ≥244,585.603045 USDT
- strict Exchequer-derived minimum
Recorded transfers
- BOS Exchequer0.02221978958 RBTC
- Exchequer DDstables · ETH · BNB
- DD / 509 shared railsrecipients and exchange terminals
On-chain fact
All 24 DD recipients also appear in 0x509201’s genuine USDT payment history
Twenty-three were paid by 0x509201 before DD first paid them; the remaining address was paid later. Repeated recipient batches and exact amount matches establish that DD entered an existing 0x509201 recurring-payment network.
Collective lower bound
At least 411,750.640097 units reached payees or the common terminal
The bound charges every available unrelated DD unit and the full March route dilution against the Exchequer lot before attributing any remaining amount. It avoids adding overlapping subset bounds.
Controller attribution
Organizational roles are visible; most human key holders remain unresolved
Yago and Nahari are connected through documented management, finance, policy, and public-explanation roles. Tyrone is tied to 8C through the preserved supplied account record and on-chain-matched session. The public record identifies 0x509201 as a shared operations address; its natural-person controller remains unidentified.
- Separate funding described
Yago said Sovryn had not funded BitcoinOS and that Sovryn’s treasury was not being requested.
- A large contribution path described
He said Sovryn would need to invest or provide $5 million–$100 million in value or in-kind support (opens in a new tab) for its 10% BOS interest.
- Broad contributions authorized and acknowledged
SIP-0083 (opens in a new tab) described substantial prior Sovryn contributions and further technical, audit, marketing, infrastructure, and network-operation support.
- Cross-payments acknowledged; mingling denied
Yago said BOS had paid obligations on Sovryn’s behalf (opens in a new tab) , then answered “No” (opens in a new tab) when asked whether the projects were mingling funds.
Accounting and legal inquiry
Cross-project value transfer
Why the shared routes support an embezzlement and related-party-diversion inquiry
The public record now establishes more than shared personnel. Sovryn assets entered custody and payment infrastructure controlled by the same owner-address set used for official BOS administration; BOS collector-wallet funds and Exchequer-derived assets converged at exact exchange routes; and 0x509201 both received and approved payments from the shared DD Safe.
The Exchequer assets were liquid BTC, stablecoins, ETH, and BNB. Yago described Sovryn’s BitcoinOS interest as 10% of BOS supply. A token allocation has different liquidity, control, vesting, revenue, and economic rights from liquid treasury assets. Fair-value analysis requires the BOS allocation’s custody and vesting terms, its realizable value at each transfer date, BTC OS Limited’s cap table and revenue rights, and the consideration Sovryn received for every contribution.
Dossier conclusion: these facts support investigation of whether Sovryn property held for its SOV stakers was diverted to BitcoinOS, related parties, or personal benefit without valid authority, fair consideration, complete disclosure, or reimbursement.
- On-chain facts
- Shared Safe owners, concentrated approvals, recurring payees, wallet-level pooling, and exact Bitcoin and Ethereum off-ramp reuse.
- High-confidence Origins attribution
- The Bitcoin and Cardano pool assignments are supported by sale timing, unique-deposit sweep topology, collector rotation, and cross-chain synchronization. Origins and Fireblocks hold the confirming vault map.
- Purpose and beneficial ownership
- Invoices, project codes, exchange KYC, trades, withdrawals, intercompany entries, and payee identities allocate what the transfers purchased and who received the economic benefit.
- Embezzlement referral
- Investigators should trace authority, accounting treatment, purchased work, reimbursement, and ultimate benefit—and identify whether any Sovryn property financed BitcoinOS or a related party without fair value returning to SOV stakers.
Priority records: Origins/Fireblocks order and vault exports; Gemini and other exchange address-assignment, KYC, trade, withdrawal, and bank files; Sovryn and BTC OS Limited general ledgers and due-to/due-from accounts; DD/509 payee identities, invoices, payroll, and project codes; Exchequer budgets and approvals; BOS allocation valuation and custody; and private-key and instruction records for the shared owners.
Next: the sale claims and technical audit. The fund-flow record answers where reconstructed sale proceeds went and fixes the scale of the solicitation. Part V compares what BOS purchasers were told with the public bridge and code available while those funds were raised. Read the sale-claim audit.
Part V · BOS sale claims
BOS was sold with trustless-bridge claims while the public bridge was unfinished
Origins records 609,509,366.81 BOS sold and $4,888,380.30 in its USD-valued amount-collected counter. During that sale, official materials described trustless Bitcoin bridging without a multisig or federation. The public product was one-way and used valueless test assets; the reviewed public code implemented a two-party optimistic verifier and left the complete production bridge unfinished.
What the audit found
The reviewed public code implemented a two-party optimistic verifier; the advertised bridge additionally required custody, multiparty, two-way, recovery, and liquidity components. Think of BitSNARK less like a vault that automatically rejects a false withdrawal and more like a timed alarm-and-dispute system: an informed, funded watcher must detect a bad claim and complete the required Bitcoin challenge before the deadline.
- Public artifact
- The repository contained a two-party proof checker and dispute prototype. The marketed bridge required additional custody, multiparty, two-way, recovery, and liquidity systems.
- Where trust remains
- If no effective challenge completes, a false claim can reach the claimant path under the stated timeout and transaction conditions. Pre-signing adds a separate trust condition: a mandatory signer must never approve a hidden alternative, and after the allowed transactions are signed, at least one of the two required signing capabilities—and every copy or backup of it—must become permanently unusable. Bitcoin cannot verify either fact.
- What was publicly available during the sale
- The 16 February launch used valueless test assets and moved one way from Bitcoin Testnet 3 to EVM testnets. BitcoinOS described the return prover, two-way path, multiparty verification, and Grail code as future work while the sale used present-tense “trustless” claims.
The findings show a concrete gap between categorical no-counterparty marketing and the conditional public design. That substantiation gap warrants investigation into whether sale-linked descriptions gave purchasers a misleading or incomplete impression.
What purchasers were told
On 29 January 2025 (opens in a new tab) , Edan Yago said BTC could move across chains trustlessly “without having to use a multisig or a federation.” A 19 February paid promotion (opens in a new tab) quoted him saying users could experience “truly trustless Bitcoin bridging.”
The 27 February sale page (opens in a new tab) said BitcoinOS enabled any blockchain to connect with Bitcoin trustlessly and placed that representation beside BOS purchases and possible annual revenue flows above $7 billion. The 3 March sale notice (opens in a new tab) repeated the trustless claim with a purchase call to action, escalating stages, bonuses, referrals, and a $50 minimum.
What was publicly available during the sale
The 16 February launch record (opens in a new tab) described valueless test assets, a one-way Bitcoin Testnet 3-to-EVM path, and a return prover and two-way bridge still being built. The reviewed repository described a local two-party regtest demo while multiparty verification, two-way operation, and Grail code remained future work.
Origins’ two completed backend periods record the full launchpad sale. The first completed period (opens in a new tab) and its post-maintenance continuation (opens in a new tab) record 609,509,366.81 BOS in tokensSold and $4,888,380.30 in the USD-valued usdCollected counter across accepted crypto assets. The first period includes the issuer’s $2.225 million Phase 1 result (opens in a new tab) ; the displayed total is the sum of the two completed periods.
Measurement: first-party Origins API counters. Audited net proceeds and the composition of purchased, bonus, referral, and staker allocations require issuer, banking, and subscription records. The sale-total record preserves both periods, exact decimals, response snapshots, scope, and exclusions.
The sale claims, in Edan Yago’s and Gadi Guy’s own words
Hear the representations before inspecting the technical record beneath them. The recordings establish what was said; the code, symbolic model, signature rules, and bounded lab record establish what the public system could substantiate.
Yago says Bitcoin can have “truly trustless” layer twos
Excerpt checked against the full source recording
“It allows Bitcoin to have truly trustless layer twos—rollups where any type of functionality can occur.”
Watch the full BitcoinOS presentation on YouTube (opens in a new tab) · source recording and captions checked
Yago presents Grail as cross-chain BTC without a multisig or federation
Excerpt checked against the full source recording
“take BTC and move it across chains trustless, without having to use a multisig or a federation.”
Watch the full BitcoinOS keynote on YouTube (opens in a new tab) · source recording and captions checked
Guy says BitSNARK enables trustless bridges without counterparty risk or a person or group able to steal funds
Excerpt checked against the full source recording
“There is no person or—or group of persons who together can steal your money.”
Watch the full Bitcoin Magazine NL interview on YouTube (opens in a new tab) · source recording and captions checked
Later acknowledgments: in April, Guy said Grail still needed productionization (opens in a new tab) . In June, Yago acknowledged additional trust assumptions (opens in a new tab) . Those statements confirm conditions omitted from the categorical sale language.
Inspect the detailed BOS sale-wallet and cross-project control record
Sale proceeds · wallet reconstruction
Detailed Ethereum BOS collector and downstream-route record
Origins’ unique-deposit-address model (opens in a new tab) left a repeatable on-chain fingerprint. Exact buyer payment, deposit-address sweep, common gas funding, published stage price, collector succession, and official vesting-beneficiary matches identify three rotating primary Ethereum collectors with high confidence. The same method also identifies a smaller associated branch at 0x60c507….
A sale gas wallet activated isolated deposit addresses with 0.001 ETH. Each address received a participant’s canonical token and swept the identical raw amount into a collector. The early gas wallet funded the middle gas wallet (opens in a new tab) and the later multichain gas wallet (opens in a new tab) ; the middle wallet also funded the later one (opens in a new tab) . This links all three primary collector generations independently of address labels. The 60c branch adds five exact payment-and-sweep pairs through four new deposit addresses. (opens in a new tab) The full reconstruction contains 144 exact purchase sweeps across 127 participant deposit addresses; forty-three payment-source addresses also appear as beneficiaries in the official Community Sale vesting record. These are discovered lower bounds because Origins permitted exchange deposits and separate payment and claim wallets.
-
01 · Early BOS Ethereum collector
0xBb55bB…243243- Exact sweeps
- 79
- Deposit addresses
- 68
- Payer = beneficiary
- 22
3 Mar 2025–12 May 2025. Gas funder
0x528D59cA…d6753a. -
02 · Middle BOS Ethereum collector
0xFeD3a5…fF0628- Exact sweeps
- 27
- Deposit addresses
- 26
- Payer = beneficiary
- 8
13 May 2025–30 Jun 2025. Gas funder
0x8bb0d983…e23c7a. -
03 · Post-maintenance multichain BOS collector
0x1160A7…abf08C- Exact sweeps
- 33
- Deposit addresses
- 29
- Payer = beneficiary
- 14
10 Jul 2025–22 Oct 2025. Gas funder
0x64f842e5…c2afa3.
Other verified chains: the same 1160 collector also received participant-specific deposits on Arbitrum (opens in a new tab) —about 3,841 ARB and 0.191 ETH—and Polygon (opens in a new tab) —about 1,335 USDT and 389 POL. The Arbitrum balance moved to one unlabeled address; the reviewed Polygon record establishes receipt but no onward destination. Exact values remain in the wallet-flow record.
Early collector · exchange endpoint
About $102,167 in canonical stablecoins, plus WBTC and ETH, reached Binance 14
BB55 moved pooled balances through 0x6C250D…6038. That relay sent 102167.018527 USDT/USDC/DAI units, 0.00274432 WBTC, and 27.157479067347059439 ETH into the publicly labeled Binance 14 address. Inspect the route. (opens in a new tab) The credited customer account is identifiable from Binance and Fireblocks records.
Middle collector · project operations
Middle-period assets reached both an operational wallet and 0x509201 directly
FeD3 sent 43585.792331 USDT/USDC units and 5.799965340728752 ETH to 0x4ad662…D4a. That wallet was first funded by 0x509201…AbD6 (opens in a new tab) and later sent 23,000 USDT and 5,000 USDC (opens in a new tab) back. FeD3 also sent 4937.393862 canonical stablecoin units, 0.001 WBTC, and 1.196003859314349906 ETH directly to 0x509201 (opens in a new tab) . It and 1160 later reused the early Binance relay (opens in a new tab) . The pooled 4ad account requires its internal ledger to assign each payment after receipt.
Post-maintenance collector · direct 0x509201 route
About $234,160 in stablecoins and 3.6055 ETH went directly to the shared operations address
On 14 November 2025, 1160 sent 204103.50752 USDT (opens in a new tab) , 30056.588245 USDC (opens in a new tab) , and 3.605528140408725578 ETH (opens in a new tab) to 0x509201…AbD6 . That address already links B7, Sovryn’s official Ethereum bridge, DD, and the official BOS Safe family.
0x509201 moved most of the 14 November collector-wallet stablecoin lot
Two primary reconstructed collector wallets sent $238,982.49 in USDT and USDC face value directly to the shared operations address on 14 November 2025. By 30 November, balance conservation establishes that at least $226,480.57—94.77% of that designated lot—had left.
- Received
- $238,982.49
- Minimum moved
- $226,480.57
- Labeled exchange endpoints
- ≥$183,433.94
- 1 Identified BOS collectors $238,982.49 USDT and USDC sent directly
- 2 Shared operations address
0x509201…AbD6Funds pooled before dispersal - 3 Gemini · Kraken · Coinbase at least $183,433.94 Reached publicly labeled exchange addresses
Why the lower bound is certain
The calculation first assigns every outflow to the wallet’s pre-existing and other available stablecoins. Only the remainder is assigned to the collector lot. This produces a source-neutral minimum even though token units become fungible when pooled.
The first-hop bound is $183,441.68. After deducting 4.743054 of swap loss and 3 USDC already in the Kraken relay, at least $183,433.94 reached the publicly labeled exchange addresses.
The clearest route ends at Gemini
0x509201 sent exactly 200,000 USDT to an EIP-1167 proxy in a publicly labeled Gemini deployment system (opens in a new tab) ; on 25 November the proxy sent the exact amount to the address publicly labeled Gemini 4 (opens in a new tab) . Since the wallet held only 49,536.080261 USDT before the collector receipts, more than $150,463 of that deposit had to come from the designated lot. Routes ending at publicly labeled Kraken (opens in a new tab) and Coinbase (opens in a new tab) addresses raise the strict exchange-endpoint minimum to $183,433.94.
BNB Chain followed a different path
The same known collectors sent $7,857.87 in USDT and USDC to the same address (opens in a new tab) . The complete canonical-token history contains no later non-zero outflow (opens in a new tab) , and current balances exceed the traced receipts. That lot remained conserved at 0x509201 through the research cutoff. The separately identified 60c Origins branch swept another 202.9888302 BSC stablecoins and 2.346967086497769 BNB to 0x509201 (opens in a new tab) ; assigning those BNB-side receipts to individual orders requires the Origins ledger. A separate FeD3 route sent about $20,638.70 through the reused relay to a publicly labeled Binance wallet (opens in a new tab) .
Ethereum and BNB stablecoins form one defined slice
The matched canonical-stablecoin face value equals 6.29% of Origins’ $4.89 million usdCollected counter; the expanded canonical-stablecoin reconstruction reaches 7.04%. The sale-wide multichain benchmark above also covers Cardano, Bitcoin, and other non-overlapping canonical stablecoin paths.
TGE and vesting record
The official Community Sale vault created 1,162 cancellable schedules
The Ethereum vault (opens in a new tab) created schedules for 1,141 beneficiaries totaling 351,227,296.06 BOS. That equals 57.62% of Origins’ tokensSold counter. The remaining 258,282,070.75 BOS requires reconciliation across late wallet submissions, other distribution paths, cancellations, bonuses, and the complete order ledger.
Administrative power
The same BOS owner Safe holds forfeiture and salvage authority
Every decoded schedule is cancellable. An emergency cancellation of two schedules (opens in a new tab) moved 496,028.63 BOS of unclaimed vested and unvested principal to the official BOS owner Safe, which forwarded the same amount to the original vault deployer in the same batch. That owner Safe uses the five-address control set shared with DD.
Investor diligence
Cross-project control risk
Detailed BitcoinOS operational and bridge-control risk record
BitcoinOS identifies Edan Yago as co-founder and CEO and Elan Nahari as co-founder and COO (opens in a new tab) . The 2025 BTC OS Limited MiCA filing (opens in a new tab) lists Yaron Edan Yago as the only named management-body member and says the company issues and supports BOS and coordinates contributors. On-chain records identify part of the shared infrastructure: the DD wallets that received Sovryn treasury-derived assets have the same five-owner set and 8C deployer as the official BOS token-owner and allocation Safes. The same two addresses repeatedly operated DD and appear throughout the BOS Safe family. Inspect the cross-project custody record above. The natural persons behind those owner addresses and the allocation of DD’s payments between projects remain unidentified.
Protective judgment: until those controls are published and independently verified, users should not entrust BTC to a BitcoinOS bridge or treat “trustless” as an operational fact or a reason to buy BOS. Test claims with valueless assets; do not substitute founder reputation or operator count for verifiable control separation.
- Documented Sovryn conduct and harm
- This dossier characterizes as theft two forms of value belonging to SOV stakers: their shared treasury assets and their promised protocol-fee rights. It documents Yago as the leader who announced and defended the policy, dismissed the lender warning, and sponsored its ratification; it places Nahari in an Exchequer finance, accounting, and reporting lane. It also documents five B7-first-funded wallets casting every vote against two executable recovery proposals, 99.32% B7-origin support for later ratification, liquidations, and separate RBTC-lender exposure. The located record contains no leadership commitment to require repayment, pause affected lending, pursue any available protective action, or independently investigate the loans after users disclosed the danger. This is the dossier’s evidence-based theft finding; authorities and courts determine criminal charges and liability.
- Why borrowing against SOV matters
- Borrowing RBTC against thinly traded SOV obtained bitcoin liquidity without an immediate market sale and transferred collateral-liquidity risk to the lending pool. At the measured snapshot, selling all eleven loans’ SOV collateral through the only identified pool under the stated assumptions left an estimated 4.0441-RBTC shortfall. The pattern warrants examination as an exit-risk scenario: it converted SOV exposure into RBTC liquidity while leaving lenders with residual collateral-liquidity risk. The B7-linked borrower cluster remains pseudonymous; authorities should compel key-custody and communications records to identify its controllers and motive.
- The protective test for “trustless”
- A bridge is meaningfully independent of leadership only if users’ BTC remains safe and redeemable when any founder, company officer, software publisher, operator, or custodian becomes dishonest, compromised, or unavailable. Reputation is not a security control. Independent beneficial control must be verified through ownership, key-custody, infrastructure, and instruction records; counts of addresses, keys, or operators are insufficient.
- Sale-period BitSNARK control surfaces
- The reviewed design depended on a capable watcher completing a funded challenge before timeout, correct setup and transaction graphs, no unauthorized alternative being signed during setup, both required script-path signing capabilities not remaining jointly available, and the discrete log for the configured Taproot internal key remaining unavailable. Under the stated premises, an invalid claim can reach the claimant path if no effective challenge confirms; if both required script-path signing capabilities survive, their holders can co-sign a fresh alternative spend through the locked-funds leaf. BitcoinOS should produce the key-generation, erasure, custody, backup, and instruction records that identify who held each capability and whether every disallowed path became unavailable.
- Later Grail Pro control surfaces
- BitcoinOS’s later architecture (opens in a new tab) uses TEE-held operator keys, mutable rosters and thresholds, and a documented 12-of-16 example. Twelve effective authorities can authorize a release; five refusals or outages leave only eleven and block the normal path. The page’s statement that twelve compromises are required for “loss of service or funds” is therefore wrong for service availability:
16 − 5 = 11 < 12. A mandatory custodian policy (opens in a new tab) can give that custodian a veto over its BTC. “Twelve authorities” is a threshold count; independence requires separate beneficial controllers, infrastructure, update paths, and recovery powers. - Frontend and software-publisher risk
- BitcoinOS’s own trust model says users trust the frontend (opens in a new tab) , which queries operator keys to generate Taproot deposit addresses. Its operator instructions use the mutable image tag
grailpro/cosigner:latest(opens in a new tab) , not a pinned digest. A substituted roster or address could send a deposit outside the intended quorum. The tag can change what a later pull resolves to; if operators deploy it and the admission policy accepts it, one shared faulty or malicious release could affect nominally separate operators. The reviewed record leaves the referenced frontend audit, expected enclave measurement, immutable image digest, update approver, release history, allowlist, attestation log, and controller unidentified. - Company-level access and loss terms
- A pinned public Grail frontend source file (opens in a new tab) contains terms that call BTC OS Limited the “Bridge Operator,” say reverse redemption is supported only where technically feasible, warn of partial or total loss, and reserve company discretion to suspend or restrict access. BitcoinOS should produce the versioned deployment, presentation, acceptance, custody, and service-access records that establish when those terms operated and who exercised the reserved authority.
- Records still needed
- Before anyone relies on “trustless” or “decentralized,” BitcoinOS should publish the production operator and custodian roster; legal and beneficial-controller mapping; vault addresses and scripts; key-generation and erasure evidence; internal-key custody; challenger funding and data plans; roster, threshold, software, emergency, and recovery authority; reproducible source and build hashes; TEE measurements and approval logs; independent audits; incident history; and BOS source-and-use-of-funds accounting.
Inspect the full technical proof and claim chronology
Technical terms, translated
- Zero-knowledge proof
- A cryptographic proof of a statement defined by a circuit, verification key, and public inputs. Bitcoin custody and release require separate mechanisms.
- Optimistic verification
- The complete proof is checked outside Bitcoin. Bitcoin adjudicates a disputed computation only when someone challenges in time.
- One-of-N honesty
- Safety depends on at least one watcher having the correct data, funds, and time to complete every required challenge transaction before the deadline. Being honest is not enough if the challenge is never confirmed.
- Pre-signing and key erasure
- Participants sign the allowed future transactions before funds are locked. “Erasure is a premise” means security assumes no hidden alternative was signed and that enough signing power—and every copy or backup needed to restore it—then became permanently unusable. Bitcoin can verify the signatures, but not either off-chain fact.
- Safety versus liveness
- Safety asks whether an invalid claim can release funds. Liveness asks whether an honest user can complete a withdrawal.
- TEE
- A protected hardware environment—documented for later Grail Pro as AWS Nitro—relied on to run approved code and protect keys.
The counterexamples and their premises
A universal security claim fails when one permitted adverse execution exists. BitcoinOS’s own transitions and script supply the protocol premises; a separate valueless Core lab run tests only the analogous threshold-signature principle.
The published symbolic model lets ProofUncontested consume Locked Funds without consulting IsProofValid. An audit patch specializes the model’s fixed CHOOSE expression to false and adds a strong label-preservation invariant. TLA+ TLC returned this three-state symbolic trace:
- InitLocked funds exist.
- ProofThe prover publishes an invalid asserted result.
- ProofUncontestedThe locked-funds label disappears into the prover path.
Result and premises: TLC proves symbolic reachability in this abstract model. Applying that trace to Bitcoin requires a matured timelock, unspent inputs, an available valid presignature, no effective challenge, and confirmation of ProofUncontested; CSV time, signatures, value, ownership, recipients, and Bitcoin consensus sit outside the model.
The intended locked-funds Tapscript leaf checks one prover signature and one verifier signature. It contains no proof predicate or opcode-level output covenant. Its acceptance condition reduces to:
Accept(T) = Verify(pkP, sigP, T) ∧ Verify(pkV, sigV, T)
Taproot SIGHASH_DEFAULT binds the transaction outputs, so old signatures cannot simply be copied to a changed recipient. But if both signing capabilities survive—or both parties pre-sign that exact alternative before erasure—they can authorize it. The finite coalition model finds 1 authorizing coalition out of 4, with a minimum of 2 capabilities.
Result and premises: the intended script leaf permits the two holders to authorize a fresh spend if both signing capabilities survive. The whole P2TR output also has a configurable internal-key path. Safety therefore relies on a correct finite graph, output-binding signatures, an unavailable internal-key discrete logarithm, and effective deletion or non-retention of at least one of the two required script-path signing capabilities.
An isolated Bitcoin Core v31.1 regtest used P2WSH/ECDSA, legacy OP_CHECKMULTISIG, and SIGHASH_ALL. It accepted and mined a prescribed two-of-two spend. Copying the signatures onto a changed recipient failed; freshly signing that alternative with both retained keys succeeded; one signature failed.
Lab scope: the experiment establishes the output-binding and retained-key proposition in a generic P2WSH/ECDSA analogue. Exact BitSNARK P2TR/Tapscript/Schnorr replay remains unreproduced, and the public packet lacks a deterministic replay fixture. Bitcoin verifies signatures and transactions, not erasure. A public, independently audited setup and custody record can provide evidence of deletion; it cannot rule out a hidden copy or secretly pre-signed alternative.
Verified capabilities in the public code
The reproduced public result was an optimistic verifier prototype. The bridge marketed to purchasers also required custody, networking, redemption, recovery, and liquidity systems.
Reproduced successfully
- v0.1: 56 of 56 public tests passed.
- v0.2: TypeScript compiled; 154 tests passed and two were skipped.
- The separate decoder test verified its supplied Groth16 witness.
- The public code implements a real two-party optimistic dispute prototype.
Capabilities absent from the reproduced results
- The only Circom statement in the reviewed v0.2 tree was a fixed multiplier test, not dynamic bridge inclusion, burn, amount, or recipient data.
- The repository contained no executable two-way Grail custody, mint/burn, redemption, operator, recovery, or liquidity system.
- A Jest end-to-end test was skipped, while a separate Docker-dependent local two-party regtest demo remains unreproduced; this audit therefore contains no reproduced networked multiparty two-way bridge result.
- Any private prototype sits outside the reviewed public tree and requires production source, build, audit, and deployment evidence for assessment.
Later Grail Pro documentation confirms a different conditional trust model
Grail Pro is a later architecture, separate from the sale-period design. Its first-party documentation shows a production-facing system dependent on institutional operators, protected hardware, and threshold authorization—not ZK alone.
The documented 12-of-16 example
BitcoinOS’s architecture (opens in a new tab) says operators verify proofs in AWS Nitro enclaves and authorize Bitcoin releases through a threshold. A dated article (opens in a new tab) gives twelve signatures out of sixteen as its example.
- Minimum effective signing coalition
- 12 of 16
- Authorizing subsets, including supersets
- 2,517
- Minimum refusals that block the normal threshold path
- 5
- If a distinct custodian is also mandatory
- 13 minimum; custodian alone can veto
- If the custodian is one of the 16
- 12 including it; custodian alone can veto
Deployment scope: custodian membership remains ambiguous, so both cases are shown. Authority counts and human counts are distinct: enclave isolation could require separate compromises, while common build, attestation, roster, cloud, recovery, or implementation control could affect many. The minimum human coalition remains indeterminate until BitcoinOS publishes the topology, beneficial-control map, and reproducible Grail Pro code. These figures count logical coalitions rather than probabilities.
An expert warned Yago months before the sale
On 24 July 2024, Weikeng Chen challenged whether the announced mainnet result supported the covenant and bridge claims being made and urged Yago to scrutinize what his technical team had told him. The later audit confirms the core concern: the public record showed a proof-verification milestone, not a completed public two-way trustless bridge.
What Chen warned about—and what the code shows
- The warning: after a participant linked the BitcoinOS announcement, Edan Yago said BitcoinOS had done it on mainnet (opens in a new tab) . Chen challenged the covenant claim (opens in a new tab) and urged Yago to scrutinize the technical team’s representations (opens in a new tab) .
- The audit’s central finding: the identified transaction supports a real proof-verification milestone, but the reviewed public code was a two-party optimistic verifier—not a completed, public, two-way bridge that removed counterparty trust. Its safety depended on a timely challenger, correct setup, a complete pre-signed transaction graph, no complete signing coalition remaining available, no secretly pre-signed alternative, and an unavailable Taproot internal-key discrete logarithm.
- The later audit: Chen challenged the mainnet covenant claim and warned Yago to scrutinize his technical team’s representations. The audit found the same substantive gap: the public artifact was a two-party optimistic verifier whose safety depended on off-chain setup, key deletion, and active challenge—not the completed trustless bridge later marketed beside the BOS sale.
- Relevance to the BOS sale: trust, setup, challenge, and implementation scope were disputed publicly months before categorical bridge statements were used to promote BOS. The thread establishes contemporaneous notice; the code audit independently establishes the substantiation gap.
Method: Telegram supplies the dated warning and Yago’s response. Pinned source code, executable tests, an audit-patched symbolic TLA+ trace, finite coalition arithmetic, Bitcoin’s signature rules, and the bounded Core lab record supply the technical conclusion independently.
6730ea2e…219ac6.
c6f38239…ea32.Preservation boundary: the public message pages corroborate the displayed sequence, authors, UTC dates, and reply chain. A native Telegram Desktop export would still be the strongest record for deleted, edited, service, or media content.
| Date | Public representation or event | Verified technical or sale record |
|---|---|---|
| 23–24 Jul 2024 | BitcoinOS reported a BitSNARK mainnet demonstration (opens in a new tab) ; Yago called it done on mainnet; Chen publicly challenged the implementation and claim scope | The identified transaction and decoder establish a proof-verification milestone. A complete dispute graph and public two-way bridge remain unreconstructed, and the design adds active-challenger and setup assumptions |
| 29 Jan 2025 | Yago promoted moving BTC across chains without a multisig or federation | The pinned v0.1 baseline placed networked multiparty operation and a two-way peg in future work |
| 16–19 Feb 2025 | One-way valueless testnet (opens in a new tab) followed by a paid promotion for “truly trustless” bridging | The product record still described a return prover, two-way bridging, and mainnet delivery as future work |
| 26–27 Feb 2025 | A repository snapshot carries 26 February Git metadata; the direct presale page (opens in a new tab) followed on 27 February | The snapshot described a local two-party regtest demo and future multi-verifier/two-way work; public availability on 26 February requires hosting or release evidence |
| 3 Mar 2025 | The BOS sale opened (opens in a new tab) with categorical trustless-bridge language and a direct purchase call to action | The public bridge remained unfinished and one-way on valueless test assets |
| 20 Mar 2025 | “Fully production-ready” attributed to Yago (opens in a new tab) | The same-day issuer post (opens in a new tab) described a basic two-party regtest release and future multiparty/Grail work; exact scope remains unresolved |
| 14–24 Apr 2025 | Guy said no person or group could steal funds; BitcoinOS reported $2.225 million raised in phase one (opens in a new tab) | The same interview said Grail still needed productionization; purchaser-level exposure and reliance require account, communication, and allocation records |
| Jun–Sep 2025 | Yago acknowledged additional trust assumptions (opens in a new tab) | The MiCA paper (opens in a new tab) called Grail trust-minimised and planned a further audit before production |
| 3 Mar–22 Oct 2025 | Two completed, contiguous Origins backend periods (opens in a new tab) covered the full launchpad sale | $4,888,380.30 in the USD-valued usdCollected counter and 609,509,366.81 BOS in tokensSold; the Phase 1 report falls within the first period |
Established findings
- Technical conditions: rejecting an invalid claim requires an effective challenge to complete in time. Constraining spends to the approved graph separately requires that no unauthorized transaction was pre-signed, the two script-path capabilities do not remain jointly available, and the Taproot internal-key discrete logarithm remains unavailable.
- Substantiation gap: categorical bridge claims accompanied a sale while the public product was one-way/testnet and public two-way, networked, multiparty bridge components remained unfinished.
- Fundraising measurement: Origins supplies first-party platform counters across two completed periods. Audited net receipts and the allocation breakdown require issuer, banking, and subscription records.
Records authorities should compel
- Archived marketing, terms, disclosures, and code versions delivered to each purchaser
- Marketing approvals, technical reviews, and communications showing what each speaker knew and intended
- Dated private code, builds, audits, and deployment records claimed to support each sale-period statement
- Purchaser exposure, deposits, allocations, token disposition, reliance, causation, and loss records
- Corporate attribution, agency, jurisdiction, and records required for a final legal finding
Conclusion: taken together, the dated sale claims, public implementation limits, first-party fundraising counters, and reconstructed proceeds routes support focused investigation into what purchasers were told and how their payments were controlled and used. Audited net receipts, knowledge, reliance, causation, and loss require the private records identified above. Read the full proof, dated claim matrix, sale-total record, wallet-flow record, and 0x509201 follow-through record.
Transition to recovery: the record now joins the sale claims, the system’s technical conditions, the reconstructed money paths, and the full Origins counter. Part VI identifies the purchaser, platform, code, key-custody, exchange, and accounting records needed for attribution and recovery.
Part VI · Recovery
Preserve evidence. Trace the money. Pursue recovery.
This record is built for action. Victims can document losses, reporters can verify the central claims, and investigators can preserve platform and exchange records before they disappear.
For victims
Preserve the statements and promises you relied on, along with wallet exports. Calculate deposits, withdrawals, rewards, and remaining exposure. Record the steps you took to limit harm, and submit only copies through the encrypted intake. Never submit a seed phrase, private key, or password.
Submit evidence securelyFor reporters
Start with the concise media brief, chronology, transaction set, statement-versus-record exhibits, reproducible datasets, and source index. Ask named principals for document-backed answers to the compulsory-record requests.
Read the media brief Download the full evidence packetFor authorities
Preserve exchange, platform, BitcoinOS marketing, code, bridge-control, and BOS purchaser records immediately; identify the people controlling the five shared DD/BOS owner addresses, borrower keys, and FastBTC signing keys; obtain the missing Sovryn/BTC OS Limited intercompany ledgers, DD payee file, and FastBTC closing ledger; trace the 25.66001145-BTC shutdown receipts and other centralized-exchange proceeds; and interview the named policy, accounting, and implementation principals.
Review records to preserve and obtainRecords authorities should preserve and obtain
- Immediate preservation of forum, Discord, GitHub, Google Drive, email, device, and cloud audit logs
- Natural-person and beneficial-controller identity, key custody, devices, backups, and signer logs for the 0x924f Exchequer multisig, Contracts Guardian shared wallet, B7, borrower wallets, 8C, D9, and all five shared DD/BOS owner addresses
- Centralized-exchange customer-identification, deposit-credit, trade, withdrawal, linked-account, and preservation records for
bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5and its consolidation route - Sovryn and BTC OS Limited board, leadership, committee, budget, invoice, payroll, vendor, general-ledger, journal-entry, intercompany-account, reimbursement, cost-allocation, bank, exchange, and tax records
- FastBTC’s production database, BTC deposit assignments, replenisher and payout wallet xpubs, natural-person key custody and signer logs, shutdown instructions and approvals, opening and closing reserve reports, provider contracts and capital accounts, customer liabilities, fees, rebalances, and transaction-level payment mapping
- FeeSharing tickets, code-review messages, deployment logs, instructions, and vote planning
- Borrower communications, custody logs, repayment discussions, risk review, and liquidation response
- BitcoinOS bridge-key, operator, custodian, roster, threshold, software-allowlist, code, build, audit, deployment, incident, and recovery records
- Origins and Fireblocks deposit-address, vault, sweep, workspace, API-user, policy, signer, and audit logs; Binance records for the identified relay account and later withdrawals
- BOS purchaser exposure, deposits, allocations, token disposition, reliance, causation, loss, related-party, fundraising, and source/use-of-funds records
- DD recipient identities, invoices, payroll and vendor purpose, project allocation, approvals, beneficial ownership, current custody, and subsequent asset disposition
- Victim reliance, deposits, stakes, lending claims, withdrawals, rewards, cost basis, and damages
Appendices A–C · publication record Inspect the full record Open the chronology, call evidence, source index, exhibit index, and publication status.
Record files
Open the reproducible datasets and publication materials directly, or continue into the complete appendices below.
Appendix A
Case chronology
A compact sequence for referrals and reporting. Each current-state number remains tied to its own block.
A shared wallet requiring two of three owner approvals sent 5.9 RBTC to common funding wallet B7
The transfers identify the shared wallet that funded B7 and the approving wallet addresses. Obtain account, signer, device, and instruction records to identify the people behind those approvals.
B7 funded a rapid setup batch of linked wallets
Ten newly used wallets sent their first outgoing transaction directly back to B7 73–380 seconds after B7 funded them. The timing and common destination establish a centrally directed setup session.
SIP-0012 publicly proposed funding FastBTC with 100 BTC from the Origin BTC multisig
The proposal and discussion established the approved FastBTC liquidity purpose and its operational controls. They did not disclose SOV-backed iWRBTC borrowing as the funding method.
The Exchequer transferred 50,000 SOV to owner-address 4f39 before its first direct SOV-backed RBTC loan
The transfer preceded the opening by nearly six days. Balance conservation proves that at least 16,037 SOV of the later opening collateral necessarily derived from this Exchequer receipt.
Owner-address 4f39 drew 5 RBTC against SOV, then received 120,000 SOV from the Exchequer in the next transaction of the same block
4f39 forwarded the exact 5 RBTC to FastBTC's production reserve 190 seconds later. The empty-calldata transfer increased the reserve balance by exactly 5 RBTC; it was a liquidity replenishment, not an RBTC-to-Bitcoin request. This address later opened a second 9.5-RBTC position and reappeared in the February 2026 borrowing session.
The Exchequer multisig held both FeeSharing administrative powers
The power to replace the FeeSharing code and the power to operate it remained with the Exchequer multisig at 0x924f. No later transfer of either power to a Bitocracy-controlled delayed-execution contract was found in the contract history.
4f39 and the Exchequer completed three more direct SOV-backed borrows that replenished FastBTC's RBTC payout reserve
Across the four October-November positions, the production reserve increased by the exact 34.5001 RBTC received. FastBTC's contemporaneous code establishes that this wallet paid RBTC to users after their Bitcoin deposits; the transfers were not peg-outs. No principal was retired through borrower-funded CloseWithDeposit repayment; 62 liquidations and two final collateral swaps resolved the debt from pledged SOV. These four positions represented 93.2% of opening WRBTC principal in the defined 29-position closed liquidation cohort, though only four positions by count.
B7-linked wallet 8D51 opened a leveraged SOV margin position
The marginTrade created approximately 5.637 WRBTC of protocol debt and swapped the borrowed value internally into more SOV; no RBTC was paid to the wallet. After later collateral additions and 16 liquidations, the position remained active, unsafe, and deeply undercollateralized at the pinned August 2026 snapshot. It establishes long-running linked lender exposure, but it is not a direct RBTC cash withdrawal.
February borrower wallet 4f39 transferred exactly 385,915 SOV to legacy borrower wallet 8D51, which put the full amount into three loans
The exact amount moved from the later February borrower to the legacy borrower and into the loans within 4 minutes 57 seconds, directly linking their operations.
A project Discord account displayed as Tyrone supplied the address of conversion-and-bridge wallet 8C during a live bridge session
Same-day public BOB transactions match the address, tokens, small test amounts, failure and retry, and final transfers shown in the conversation. Obtain the native Discord account and message records to authenticate the account and preserve the full exchange.
Yago publicly described BitcoinOS as separately funded and said Sovryn had not funded its development
Yago wrote that Sovryn had not funded BitcoinOS, called the developer team self-funded, described separate contributors and funding, and said Sovryn's treasury was not being requested. He repeated the current-funding distinction on Community Call 63.
Yago described the value and fundraising contribution contemplated for Sovryn's 10% BOS allocation
Yago said that, for Sovryn to receive 10%, it would need to invest between $5 million and $100 million in value or provide in-kind value to that degree; he also said Sovryn was expected to engage actively in raising BOS funds. This is a contemporaneous qualification to the June separation statements.
Official Sovryn records acknowledged substantial BitcoinOS contributions and continuing investment
SIP-0083 said Sovryn had contributed incubation, design, research, development, testing, communications, and community engagement throughout BitcoinOS development and committed further technical, audit, interface, marketing, infrastructure, and network-operation resources. Yago then called Sovryn a significant BitcoinOS participant.
The completed BOS launchpad sale recorded about $4.89 million in Origins' USD-valued amount-collected counter
Origins' two contiguous completed backend periods record 609,509,366.81050959 BOS in tokensSold and $4,888,380.29942801134947357397 in the USD-valued usdCollected field across accepted crypto assets. Public-chain reconstruction identifies non-overlapping stablecoin roots plus high-confidence Bitcoin and Cardano collection candidates. Stablecoin face value and transaction-date Kraken daily VWAP for 20.0153 BTC and 2,440,904.338471 ADA produce a $4,169,986.839549 scale benchmark, or 85.3% of the counter. This is not Origins order-time accounting or an audited net-proceeds figure; complete order, rate, refund, allocation, exchange, banking, and Fireblocks records remain required.
High-confidence Bitcoin and Cardano Origins candidates rotated collectors in synchronized batches
Seven Cardano consolidation batches and the Bitcoin collector-A consolidation occurred within 16–23 minutes on 12 May. On 13 May, the main Cardano and Bitcoin rollovers landed at successor collectors 5 minutes 15 seconds apart, and their residual transfers followed 6 minutes 48 seconds apart. Sale timing, unique-deposit topology, official BOS-recipient crossmatches on Cardano, and this independent timing fingerprint support common Origins infrastructure attribution; they do not identify a natural-person controller.
The candidate BOS Bitcoin collector deposited into the terminal later used by the Exchequer route
Eight deposits totaling 20.0975 BTC reached one exact terminal address. Conservation through the candidate collection pool establishes a 20.0111-BTC sale-window lower bound, or 20.0109 BTC after excluding both test transfers. The Origins or Fireblocks vault-to-address inventory is needed to make the candidate mapping first-party-confirmed.
Long-running Sovryn operations key 0x509201…AbD6 provisioned three later DD/BOS owner keys
The key first-funded 0x5C07…96C2, 0xe31c…67C6, and 0x59c4…ed0F with consecutive Ethereum nonces inside four minutes. The following day 8C used those addresses in the five-owner set for the official BOS token-owner and allocation Safes.
8C deployed the official BOS token-owner and allocation Safe family with one five-key control set
The token-owner Safe and the allocation Safes used the exact five owner addresses later installed on DD. Net initial allocation balances reconcile BitcoinOS's published 32% ecosystem and 35% founding-entity buckets.
The fully reconciled third Cardano sale collector funded the official BOS distributor
The collector sent 8,000 ADA through a relay that forwarded 7,998.83 ADA to the official BOS Cardano distributor. The same collector's exact root, fee, and outflow ledger reconciles to zero; the public chain establishes this use but not its internal accounting category or authorization.
The BOS token began live trading
Address 8C created the cross-chain DD shared wallets 15 days later, and Exchequer multisig asset movements began 36 days later. Obtain Sovryn/BitcoinOS allocation, proceeds, and related-party records for this period.
8C created the DD shared wallet on BNB Chain, requiring two of five owner approvals
The same address created a matching Ethereum shared wallet 63 seconds later with the same five owners and two-signature requirement.
8C created the matching DD shared wallet on Ethereum
The Ethereum and BNB Chain DD shared wallets had the same owner list and two-signature requirement, later received assets routed from the Exchequer multisig, and reused the exact five-owner set from the official BOS token-owner and allocation Safe family. The same two keys approved all 14 observed Ethereum DD executions.
Two reconstructed BOS sale collectors transferred stablecoins, WBTC, and ETH directly to 0x509201…AbD6
Collector 0x1160…f08C sent 204,104 USDT, 30,057 USDC, and 3.606 ETH. Middle collector FeD3 sent 2,798 USDT, 2,024 USDC, 0.001 WBTC, and 1.196 ETH in the same consolidation window. Their sale function is established by exact participant-deposit sweeps, linked gas infrastructure, official vesting-beneficiary matches, cutover timing, collector succession, and published stage-price corroboration. The recipient address already links B7, Sovryn's official Ethereum bridge, DD, and the official BOS Safe family.
0x509201 sent 200,000 USDT into a Gemini forwarding route that deposited the exact amount at Gemini 4
Before the BOS collector receipts, 0x509201 held only 49,536 USDT. With no material intervening USDT inflow, balance conservation establishes that at least 150,463.919739 of the 200,000-USDT Gemini deposit came from the designated collector lot. The bounded minimum entering first-hop routes that terminate at publicly labeled Gemini, Kraken, and Coinbase addresses is 183,441.682473; after route losses and relay prebalances, at least 183,433.939419 necessarily reached those labeled exchange endpoints.
Non-overlapping Exchequer and FastBTC flows placed an estimated $5.21–$5.34 million at issue
The contemporaneous-flow estimate combines $2,963,306.70–$3,091,290.88 of traced Exchequer value with $2,244,090.25 for four FastBTC shutdown terminal receipts. Each net receipt is valued once at the Coinbase BTC-USD one-minute candle close containing its Bitcoin confirmation. The FastBTC receipts comprise 14.5301 BTC from the Bitcoin-side replenisher and payout-wallet sweeps plus 11.1299 BTC from two Rootstock-side peg-out routes, totaling 25.66 BTC. The Rootstock amount is included in that total rather than added again; the $947,652.20 D9 source-time value net of the return to the Exchequer is preserved only as a non-additive branch reconciliation. Six ETHs/ETHbs source executions moved 42.972 ETH-equivalent gross, valued at $137,922.85 in both bounds; terminal reconciliation places 31.989 ETH at DD, 10.949 WETH at 8C, and 0.034 ETH-equivalent in bridge costs, slippage, and dust. The range differs because a separate confirmed 46.01000000000000002-ETHes source exit has no located far-side receipt. The calculation counts each included asset layer once and excludes returned conversion inventory, later downstream steps, unpriced or unresolved operating assets, SOV-staker fee claims, and lender shortfall. The FastBTC allocation among treasury capital, customer obligations, and provider claims remains a closing-ledger question; the estimate is value at issue, not net damages, personal proceeds, or an adjudicated amount.
Four FastBTC shutdown receipts delivered 25.66 BTC to one Bitcoin terminal
FastBTC's Bitcoin-side replenisher/deposit sweep delivered 8.1517 BTC and its payout-wallet sweep delivered 6.3784 BTC directly to bc1qccy9…adw5. Two Rootstock-side peg-out routes delivered another 11.1299 BTC to the same address, bringing the four-receipt shutdown total to 25.66 BTC. The Rootstock amount is included in that total rather than added again. The payout wallet was bc1qajsv…psvg8. The historically reconstructed staging address 18e3Ykzf…q429 retained 0.4536 BTC through the shutdown window and is not part of the four-receipt total. The public chain establishes the wallets, receipts, common destination, and subsequent exchange-style aggregation; provider claims, customer liabilities, beneficial ownership, and the credited exchange customer require private records. The later 23.1395-BTC Exchequer terminal receipts are a separate December-January route.
The same BOS collector sent swept participant RBTC into Sovryn's Exchequer multisig
Eleven participant-specific Rootstock deposit addresses swept 0.0222 RBTC into 0x1160…f08C, and every identified payer matched a later Community Sale vesting beneficiary. The collector then sent 0.0222 RBTC, net of onward transaction gas, into Sovryn's 0x924f… Exchequer. This is a direct BOS-presale-proceeds route into Sovryn's treasury and requires intercompany source-and-use reconciliation.
A priced named-asset opening cross-check valued the Exchequer at about $3.32–$3.37 million
At Rootstock block 8,265,000, the priced named-asset cross-check reached about $3.32–$3.37 million. The Exchequer also retained unpriced BOS, MYNT, POWA, and BOS-RBTC LP positions. This opening stock is not added to the later traced-flow estimate and is a cross-check rather than a literal complete treasury valuation.
Thirty-three material Exchequer multisig operations moved SOV stakers' treasury assets
The non-double-counted ledger records 30 primary exits and three final BNB bridge executions. Six primary exits moved ETHs and ETHbs through Ethereum- and BNB-side wrapper routes. Three executions sent 23.1464 RBTC out of the Exchequer, worth an estimated $2,122,679.92 in total using the one-minute Coinbase BTC-USD candle close containing each execution. The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e approved all 33 operations (33/33). Tyrone's official deployment record later names this same wallet as its sender. Only four of the eight historical Exchequer owner addresses approved any operation in this set.
All three Exchequer-derived Bitcoin releases reached the exact earlier BOS-candidate terminal
After Rootstock-to-Bitcoin bridge and Bitcoin fees, three releases delivered 23.1395 BTC into the exact address previously used by the high-confidence BOS Bitcoin candidate. OKLink labels the terminal Gemini, while BitInfoCharts labels a recurring downstream consolidator OKEx. The address reuse is exact; venue, credited customer, beneficial owner, purpose, trades, withdrawals, and fiat proceeds require private records.
Cardano sale infrastructure and mint-derived BOS funded a Minswap BOS/ADA liquidity position
The third Cardano collector sent 277,396.064793 ADA to a purpose-created controller. A mint-derived reserve sent 36,670,452 BOS to the same address. The controller placed 277,394.921276 ADA and 36,652,194.91 BOS into an order that increased the Minswap V2 pool reserves by 277,392.171276 ADA and 36,652,194.91 BOS. All 30,314,501,400,595 returned LP units remained in an unspent controller output at the research cutoff; the controller's human identity and authorization remain unresolved.
Treasury-linked DLLR was converted to ZUSD and redeemed through Zero against borrower collateral
Five Exchequer transfers sent 569,214 DLLR to conversion wallet 8C. That wallet made five matching DLLR-to-ZUSD calls and eleven successful Zero redeemCollateral calls before five follow-on transfers returned 6.2281 RBTC to the Exchequer. Zero redemptions reduce borrower debt but also remove the oracle-priced RBTC equivalent, forcing a reduction in Bitcoin collateral exposure at the redeemer's chosen time. Because 8C held commingled balances and the successful calls exceeded the identified treasury DLLR input, not every redeemed unit or returned satoshi can be assigned solely to the Exchequer funds.
Sovryn's official X account told readers to stake SOV for BTC and USD income
The post said, “Stake SOV right now to earn up to 21.37% APR BTC and USD.” The preserved official embed response and screenshot record the solicitation and its timestamp.
Wallets staked SOV and lengthened existing locks during the promotion-to-notice period
Fifteen addresses directly added 111,068 SOV in 24 transactions. Twenty addresses lengthened locks on 9,962,956 SOV in 27 transactions. Individual victim files can join these transactions to dated evidence of promotion exposure, purchase and staking decisions, and loss.
DD sent Exchequer-attributed funds through the exact BOS-linked Ethereum forwarding route
DD sent 100,000 USDT to the same e1d4 proxy used after BOS collector receipts; the proxy forwarded the exact amount to the publicly labeled Gemini 4 gateway. The January route's standalone Exchequer-origin lower bound is 66,645 USDT. Exchange records are required to identify the credited customer, trades, withdrawals, and beneficial owner.
The Exchequer's 3.65 BPRO became material RBTC before the final D9 leg
8C redeemed 3.65 BPRO for 4.4166 RBTC. That receipt commingled with 0.6146 RBTC from DOC before 5.03 RBTC returned to the Exchequer. The 4.4166 RBTC later sent from the Exchequer to D9 is already the 24 January leg of the 23.1464-RBTC route and is not added again.
Tyrone-authored code shut down principal fee claims on live Rootstock mainnet
The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e deployed the code and submitted the request to the Exchequer multisig, and enough Exchequer owners approved it. Tyrone's official deployment record names this wallet as its sender. The live shutdown lasted 44 hours 20 minutes and began before the larger 29 January BTC decline. Yago later cited the recent BTC decline when justifying the February change that stole staker fee rights.
Archived staking-page HTML records a Webflow Last Published timestamp
The preserved HTML begins with Webflow metadata dated after the January claim shutdown and before Yago's 17 February notice. Webflow revision, approval, and account logs should identify the exact page version and approvers behind that publication event.
Seven B7-funded wallets withdrew 10,048,901 SOV from staking
The withdrawals occurred in 1 hour 52 minutes 24 seconds. Four of those seven wallets then opened the February loans.
Four linked wallets opened SOV-backed RBTC loans within 15 minutes 12 seconds
The loans paid a total of 1.465 RBTC from the lender pool to the borrower wallets and added risk from selling illiquid SOV collateral in a liquidation.
Yago announced the RBTC and ZUSD payout pause and the revenue change this dossier identifies as theft
The announcement came 12 hours 35 minutes after the last linked loan opened. It said the change would follow the next payout; the Exchequer multisig still held the contract powers needed to carry it out.
The FeeSharing deployment/submission wallet at 0xfEE171…4a9e7e submitted the 100%-withholding change
A Tyrone-authored deployment commit identifies 0xfEE171…4a9e7e as the sender. That wallet deployed the replacement code and submitted the Exchequer multisig upgrade, RBTC withholding, and ZUSD withholding actions within 3 minutes 16 seconds.
The Exchequer multisig activated 100% withholding of SOV stakers' RBTC and ZUSD fee revenue
Enough Exchequer owners approved the replacement code, and the 0xfEE171…4a9e7e deployment wallet executed both token additions. Staker claim entries for these fees stopped before any Bitocracy vote.
Six linked wallets staked 6,986,587 SOV within 43 minutes 16 seconds
Three wallets that had not borrowed restaked their exact withdrawn amounts. Nearly all stakes used the same 16 February 2029 lock target.
Public Disclosure #2 warned that the linked loans threatened RBTC lenders
The notice identified all four loan transactions, asked Yago and Nahari to close the loans, and requested safer SOV-collateral rules.
B7-funded voting power defeated the SIP-0088 recovery proposals
Five B7-first-funded wallets cast all 62,572,733.758251524367271838 votes against the executable proposals to reverse the fee change and transfer FeeSharing control to Bitocracy.
Yago sponsored a proposal to ratify the already executed staking-revenue theft
SIP-0089 was expressly presented as approval and formalization after the operational decision and contract change had already occurred.
Yago acknowledged BOS-on-behalf-of-Sovryn payments and then denied fund mingling
At 35:03 on Community Call 73, Yago said BOS had paid some funds on Sovryn's behalf and that they needed year-end consolidation. At 44:42, asked whether Sovryn was mingling funds with BOS, he answered 'No.' The DD/BOS shared-control and payment record requires the intercompany ledger, payment mapping, invoices, approvals, and reconciliation supporting both statements.
Nahari answered the challenged exchange-bound RBTC route with a general third-party FastBTC-liquidity account
At 52:04–54:18 in the call, Nahari said some FastBTC funds came from third parties and that, after sunset, funds had to return to original liquidity providers. He named no provider, agreement, amount, liability date, wallet, or transaction mapping and did not reconcile the documented historical 34.5001-RBTC FastBTC reserve financing backed by Exchequer and Exchequer-routed SOV. The shutdown record identifies 25.66 BTC reaching one terminal through two direct Bitcoin-side sweeps and two Rootstock-side peg-out routes, but the public record does not allocate that inventory among treasury interests, customer obligations, or provider claims. The provider explanation remains unsupported for the challenged later 23.1395-BTC Exchequer route without a liability ledger and exact payment mapping; the later route remains analytically separate from the November shutdown receipts.
DD funds passed through 0x509201 and a sibling forwarding proxy to the same Ethereum terminal
DD sent 120,000 USDT to 0x509201, which exchanged that amount through Curve for 119,923 USDC and then sent 122,000 USDC through sibling proxy f6c8 to the same 5f65 terminal, drawing on a pre-existing USDC balance for the difference. Allocating DD's maximum other funds only once across the January and March routes and deducting maximum March dilution establishes a joint 133,809.640217-unit Exchequer-origin lower bound at the terminal. Across all DD outflows, at least 411,750.640097 nominal stablecoin units reached either that terminal or recurring recipient wallets. These are gross-arrival lower bounds, not unique dollars or proof of purpose.
Borrower-cluster value reached the wallet that later funded a Sovryn USDt0 campaign
February borrower and later hub B493 sent 0.236 RBTC to campaign signer de169, a registered owner-address of the 0x924f Exchequer multisig, which remains the current guardian of both Governor contracts. De169 later sent the transaction identified in the transaction audit as an RBTC-to-USDt0 swap and signed the 14,417-USDt0 Merkl campaign transaction. Merkl's official opportunity page identifies Sovryn as the protocol, Rootstock as the chain, an approximately 14,000-USDt0 reward pool, and a Deposit link to Sovryn's market-making dapp. Obtain the swap receipt, full account ledger, campaign authorization, and signer records to complete the source-of-funds accounting.
Nine liquidation events struck three February loans
Liquidators repaid 0.3545 WRBTC and seized 1,571,209 SOV. All four February positions remained active and unsafe at the following audit snapshot.
The pinned lender-pool snapshot showed all 11 active SOV-backed loans unsafe
At Rootstock block 9,162,594, selling all SOV collateral through the on-chain exchange pool produced a modeled 4.0441-RBTC lender shortfall.
Sovryn's live staking page continued to advertise BTC rewards and SOV purchases
The official page displayed “up to 20% APR,” “Rewards in BTC,” “Payouts in BTC,” and a “Buy SOV” button months after the 100% RBTC and ZUSD withholding action. The page HTML, screenshots, capture time, and hashes are preserved.
Appendix B
Call evidence ledger
All nine excerpts were checked against the complete calls. Their captions, continuous time ranges, visual treatment, source links, and file fingerprints are recorded with each player.
Complete question and answer on the treasury reaction, BTC exposure, and replenishment
Complete question and answer describing overall treasury consolidation
Yago responds when the founding-member loan is raised
Excerpt checked against the full call
“No, of course not. What’s it got to do with me? Or the conversation that we’re having? Like, people who own SOV can do with it whatever they choose.”
Asked whether Sovryn was mingling funds with BOS, Yago answers no
Excerpt checked against the full call
“No.”
Complete question and answer containing the general third-party FastBTC explanation
Follow-up states the duty to protect RBTC lenders from illiquid collateral
Complete question and answer containing the inability to explain the precise redemption method
Complete question and answer containing the baseless, conspiratorial, and noise response
Complete question and answer containing the bad-faith, lack-of-understanding, and no-deep-mystery response
Appendix C
Primary records and exhibits
Public links let readers inspect each source and rerun the calculations. The evidence packet preserves the datasets and methods; restricted originals and private submissions remain outside the public site.
Exhibit index
- EX-01 Theft of SOV stakers' usable treasury assetsOn-chain recordDossier conclusioncurated-transactions.json · asset-map.json · snapshots.json reproduced
- EX-02 Registered-owner-key Exchequer execution and leadership's organizational acknowledgmentOn-chain recordDirect source recordDossier conclusioncurated-transactions.json · case-chronology.json · call-excerpts.json registered-owner confirmations and leadership acknowledgment reproduced; custody and instruction records listed for allocation
- EX-03 FastBTC reserve financing, shutdown inventory, later RBTC route, and Nahari's provider explanationOn-chain recordDirect source recordDossier conclusionRecords authorities should compelasset-map.json · fastbtc-bitcoin-inventory.json · verify-fastbtc-bitcoin-inventory.mjs · loan-records.json · btc-origins-flow.json · exchequer-shared-terminal-flow.json · verify-fund-flows.mjs · snapshots.json · call-excerpts.json · sources.json 2021 staker-financed reserve direction, Bitcoin-side operating addresses, four shutdown receipts totaling 25.66001145 BTC, and the separate later Exchequer route to the exact terminal reproduced; provider and customer allocation, venue customer, beneficial owner, and exact liability-payment mapping not public
- EX-04 Staking solicitation, retained FeeSharing authority, pre-vote staking-revenue theft, and SOV-staker damagesOn-chain recordDirect source recordDossier conclusionRecords authorities should compelcase-chronology.json · snapshots.json · fee-authority-records.json · visual-exhibits.json · sources.json official representations, code, transactions, price timing, and withheld-fee arithmetic reproduced
- EX-05 Repeated SOV-backed borrowing, FastBTC reserve financing, collateral resolution, notice, response, and lender harmOn-chain recordDirect source recordDossier conclusionRecords authorities should compelcase-chronology.json · snapshots.json · loan-records.json · pool-model-inputs.json · call-excerpts.json · sources.json 2021 direct-borrow lifecycle, exact FastBTC reserve top-ups, BTC-to-RBTC contract function, historical concentration, current pool, and loss-model arithmetic reproduced; continuous media published
- EX-06 SIP-0085 outcome-determinative linked votes, SIP-0088 opposition, and SIP-0089 ratificationOn-chain recordDossier conclusionsnapshots.json · governance-attribution.json · sources.json 73 strict funding paths, attributed balances, archive-reconciled governance records, and vote arithmetic reproduced
- EX-07 Named-actor accountability and attribution recordsDirect source recordOn-chain recordDossier conclusionRecords authorities should compelactor-attribution.json · sources.json · fee-authority-records.json · asset-map.json documentary and operational attribution stated with limits
- EX-08 BitcoinOS sale claims, proceeds routes, public delivery status, and mathematically verified trust assumptionsDirect source recordOn-chain recordDossier conclusionRecords authorities should compelsources.json · bitcoinos-claim-records.json · bos-launchpad-sale.json · bos-presale-wallet-flows.json · bos-proceeds-509-trace.json · btc-origins-flow.json · cardano-origins-flow.json · exchequer-shared-terminal-flow.json · verify-fund-flows.mjs · bos-origins-home-2026-08-21.base64.txt · bos-origins-ledger-one-2026-08-21.json · bos-origins-ledger-two-2026-08-21.json · verify-bos-launchpad-sale.mjs · verify-bos-presale-wallet-flows.mjs · verify-bos-proceeds-509-trace.mjs · bitcoinos-excerpts.json · bitcoinos-trust-model.json · bitcoinos-trust-model.md · verify-bitcoinos-trust-model.mjs · bitcoinos-invalid-proof.patch · bitcoinos-invalid-proof.cfg · case-chronology.json dated claim matrix, preserved Origins counters, reconstructed EVM/BNB/Bitcoin/Cardano collection and use routes, exact shared terminals, source-neutral conservation bounds, cross-chain benchmark, pinned-code audit, consensus construction, exhaustive coalition counts, and reproducible invalid-proof counterexample; purchaser, exchange, controller, and internal records listed for completion
- EX-10 Asset tracing and media handoffOn-chain recordDirect source recordDossier conclusionRecords authorities should compelasset-map.json · media-brief.md · case-chronology.json publication media brief and asset-tracing handoff
- EX-11 Official marketing captures, supplied screenshots, and identity portraitsDirect source recordDossier conclusionRecords authorities should compelvisual-exhibits.json · actor-attribution.json · sources.json visual exhibits published with provenance and source credits
- EX-12 Common funding wallet B7: origin funding, address setup, coordinated activity, and institutional control linksOn-chain recordDossier conclusionRecords authorities should compelb7-activity-coordination.json · governance-attribution.json · snapshots.json origin funding, 73 strict paths, setup callbacks, address metrics, Exchequer and FastBTC administrative links, February stake/loan/restake sequence, and exact legacy-loan handoff reproduced; key-custody and instruction records listed for allocation
- EX-13 Borrower-cluster value path to the Sovryn USDt0 incentive campaignOn-chain recordDirect source recordDossier conclusionRecords authorities should compelloan-value-tracing.json · loan-records.json · actor-attribution.json · visual-exhibits.json · sources.json selected transfers, the identified swap transaction, campaign outflows, official Merkl opportunity, and Sovryn dapp deposit link reproduced; swap receipt, account ledger, authorization, and custody records listed for completion
- EX-14 DD, BOS sale proceeds, and BitcoinOS shared custody, signer, deployment, and payment infrastructureOn-chain recordDirect source recordDossier conclusionRecords authorities should compeldd-bitcoinos-control.json · bos-presale-wallet-flows.json · verify-bos-presale-wallet-flows.mjs · bos-proceeds-509-trace.json · verify-bos-proceeds-509-trace.mjs · btc-origins-flow.json · cardano-origins-flow.json · exchequer-shared-terminal-flow.json · verify-fund-flows.mjs · asset-map.json · case-chronology.json · bitcoinos-claim-records.json · sources.json cross-chain Safe deployments, exact owner-set overlap, execution quorums, BOS allocations, reconstructed EVM/BNB/Bitcoin/Cardano collection routes, 0x509201 exchange routes, exact Bitcoin and Ethereum terminal reuse, Exchequer deposits, Cardano distributor/liquidity uses, B7 and Sovryn bridge links, DD payments, and statement chronology reproduced; exchange, beneficial-controller, and intercompany accounting records listed for completion
Public source index
- 2026-03-08 Public Disclosure #1 — Exchequer RBTC to exchange-style cluster (opens in a new tab) originating investigation
- 2026-03-08 Public Disclosure #2 — Founding-member SOV collateral loan (opens in a new tab) originating investigation
- 2026-03-28 Public Disclosure #3 — Exchequer total assets withdrawn (opens in a new tab) originating investigation
- 2026-08-18 Public Disclosure #4 — SOV loans liquidate, bad debt, and profit trail (opens in a new tab) originating investigation
- 2026-02-17 Staking update: temporary adjustment to staking rewards (opens in a new tab) direct statement
- 2024-12-08 BOS token and the premium future of Sovryn (opens in a new tab) direct statement on SOV yield and staking desirability
- 2023-02-22 Mo' money, less problems (opens in a new tab) direct statement on protocol revenue and SOV-staker yield
- 2026-02-17 Yago statement that staking should remain compelling and distributions should come from real revenue (opens in a new tab) direct statement on staking materiality
- 2026-03-23 Ratification of temporary revenue redirection to Exchequer (opens in a new tab) direct statement
- 2020-12-15 DeFi on Bitcoin gets a boost as Sovryn launches on RSK (opens in a new tab) official leadership record
- 2020-12-16 Greenfield leads Sovryn funding round (opens in a new tab) contemporaneous founder record
- 2021 SIP-0012 — Provide treasury funds to FastBTC (opens in a new tab) governance and contract-address record
- 2021-03-09/2021-03-10 SIP-0012 public proposal and FastBTC custody discussion (opens in a new tab) governance proposal and contemporaneous operational record
- 2021-07-12 FastBTC BTC-to-RBTC relay and production configuration (opens in a new tab) official code, direction, and production-address record
- 2020-12-03 ManagedWallet source matching FastBTC's 2021 production reserve (opens in a new tab) official deployed-contract source record
- 2025-11-21/2025-11-27 November 2025 FastBTC Rootstock reserve, D9 peg-outs, and residual return (opens in a new tab) primary on-chain transaction record
- 2025-11-25/2025-11-26 November Exchequer ZUSD conversion, Zero redemption, and RBTC-return cycle (opens in a new tab) primary on-chain transaction record
- 2025-11-18/2025-11-24 Small November Exchequer RBTC and BOS operating transfers (opens in a new tab) primary on-chain transaction record
- Undated Bidirectional FastBTC payout and replenisher architecture (opens in a new tab) official technical architecture record
- 2025-11-21/2025-11-26 FastBTC Bitcoin-side reserve sweeps to the common exchange terminal (opens in a new tab) primary on-chain transaction record and operational reconstruction
- 2025-11 Sovryn announces FastBTC sunset and withdrawal deadline (opens in a new tab) official shutdown announcement
- Undated SIP-0015 — Sovryn Treasury Management (opens in a new tab) governance record
- 2021-04-27 Sovryn Exchequer Committee meeting summary — 27 April 2021 (opens in a new tab) executive treasury record
- Undated SIP-0041 — Role assignments and wallets (opens in a new tab) governance record
- Undated SIP-0046 Part 1 — Contract ownership transition (opens in a new tab) governance record
- Undated SIP-0047 — Bitocracy Guardian (opens in a new tab) governance record
- 2024-12-06 SIP-0085 — BOS token distribution within Sovryn (opens in a new tab) governance record
- 2022-03-27 SIP-0043 is live — critical governance bug fix (opens in a new tab) governance rule record
- 2026-03 SIP-0088 — Emergency revert FeeSharing changes and transfer ownership to Bitocracy (opens in a new tab) governance record
- 2026-03-08 Yago response on intended FeeSharing contract control (opens in a new tab) direct statement
- 2026-02-25 FeeSharing 100% withholding implementation merge (opens in a new tab) code record
- 2026-02-19 FeeSharing token-withholding implementation pull request (opens in a new tab) code and implementation record
- 2026-02-19 FeeSharing deployment artifact (opens in a new tab) code record
- 2026-01-28 Temporary FeeSharing claim-shutdown commit (opens in a new tab) code and implementation record
- 2026-01-12 Stake SOV right now to earn up to 21.37% APR BTC and USD (opens in a new tab) official SOV-staker solicitation
- 2026-01-12 Official X oEmbed record for Sovryn staking promotion (opens in a new tab) official platform record
- Undated Sovryn Staking contract on Rootstock (opens in a new tab) on-chain contract record
- Undated Official Sovryn staking event definitions at immutable commit (opens in a new tab) technical primary record
- Undated Sovryn official channels directory (opens in a new tab) official account record
- Undated Stake SOV to earn BTC (opens in a new tab) official product representation
- 2026-08-20 capture Sovryn staking — rewards and payouts in BTC (opens in a new tab) official current SOV-staker solicitation
- Undated Earn with Sovryn — staking revenue description (opens in a new tab) official product representation
- 2024-09-11 Stake SOV to Earn Bitcoin (opens in a new tab) official product representation
- 2026-01-28 BTC-USD five-minute candles — January 28, 2026 (opens in a new tab) primary market data
- 2026 BTC-USD daily candles — January and February 2026 (opens in a new tab) primary market data
- 2025-12-01 BTC-USD five-minute candle at the 1 December Exchequer snapshot (opens in a new tab) primary market data
- 2025-12-04 BTC-USD one-minute candle containing the 4 December Exchequer RBTC execution (opens in a new tab) primary market data
- 2026-01-22 BTC-USD one-minute candle containing the 22 January Exchequer RBTC execution (opens in a new tab) primary market data
- 2026-01-24 BTC-USD one-minute candle containing the 24 January Exchequer RBTC execution (opens in a new tab) primary market data
- 2026-01-22 BTC-USD one-minute candle containing the BPRO redemption (opens in a new tab) primary market data
- 2025-11-21 BTC-USD one-minute candle containing the 21 November FastBTC source transfer (opens in a new tab) primary market data
- 2025-11-25 BTC-USD one-minute candle containing the 25 November FastBTC source transfer (opens in a new tab) primary market data
- 2025-11-26 BTC-USD one-minute candle containing the 26 November FastBTC source transfer (opens in a new tab) primary market data
- 2025-11-26 BTC-USD one-minute candle containing D9's 26 November return to the Exchequer (opens in a new tab) primary market data
- 2025-11-21 BTC-USD one-minute candle containing the replenisher-reserve shutdown sweep (opens in a new tab) primary market data
- 2025-11-23 BTC-USD one-minute candle containing the first Rootstock-reserve terminal receipt (opens in a new tab) primary market data
- 2025-11-26 BTC-USD one-minute candle containing the payout-multisig shutdown sweep (opens in a new tab) primary market data
- 2025-11-27 BTC-USD one-minute candle containing the second Rootstock-reserve terminal receipt (opens in a new tab) primary market data
- 2025-12-18 BTC-USD one-minute candle containing the 18 December Exchequer SOV transfer (opens in a new tab) primary market data
- 2025-12-23 BTC-USD one-minute candle containing the 23 December Exchequer SOV transfer (opens in a new tab) primary market data
- 2025-12-01 ETH-USD five-minute candle at the 1 December Exchequer snapshot (opens in a new tab) primary market data
- 2025-12-08 ETH-USD one-minute candle containing the first 8 December Exchequer ETHes exit (opens in a new tab) primary market data
- 2025-12-08 ETH-USD one-minute candle containing the second 8 December Exchequer ETHes exit (opens in a new tab) primary market data
- 2025-12-10 ETH-USD one-minute candle containing the 10 December 12:38 Exchequer ETHs and ETHbs exits (opens in a new tab) primary market data
- 2025-12-10 ETH-USD one-minute candle containing the 10 December 20:31 Exchequer ETHs exit (opens in a new tab) primary market data
- 2025-12-11 ETH-USD one-minute candle containing the 11 December 02:35 Exchequer ETHs exit (opens in a new tab) primary market data
- 2025-12-11 ETH-USD one-minute candle containing the 11 December 02:37 Exchequer ETHbs exit (opens in a new tab) primary market data
- 2025-12-11 ETH-USD one-minute candle containing the 11 December 15:08 Exchequer ETHs exit (opens in a new tab) primary market data
- 2025-12-18 ETH-USD one-minute candle containing the 18 December Exchequer ETHes exit (opens in a new tab) primary market data
- 2025-12-01 BNB-USDT five-minute candle at the 1 December Exchequer snapshot (opens in a new tab) primary market data
- 2025-12-11 BNB-USDT one-minute candles containing the two early 11 December Exchequer BNB exits (opens in a new tab) primary market data
- 2025-12-11 BNB-USDT one-minute candle containing the later 11 December Exchequer BNB exit (opens in a new tab) primary market data
- Undated Sovryn PriceFeeds contract used for SOV/WRBTC execution-block marks (opens in a new tab) deployed on-chain price record
- Undated Sovryn mainnet contract registry (opens in a new tab) official technical primary record
- Undated BPRO token (opens in a new tab) official product description
- 2021 The journey of Sovryn mutant Franklin Richards (opens in a new tab) official technical-lead identity record
- Undated Sovryn Community Call #72 (opens in a new tab) direct statement
- Undated Sovryn Community Call #73 (opens in a new tab) direct statement
- Undated Bitocracy 3.0 and Bitcoin 2.0 (opens in a new tab) direct statement
- Undated Sovryn raises $5.4 million; user-ownership representations (opens in a new tab) organizational statement
- 2026-03-19 Sovryn Financial Report Q4 2024–Q4 2025 (opens in a new tab) management report
- 2021-04-14 DeFi Technologies announces co-investment into Sovryn (opens in a new tab) official contributor identity record
- Undated Fee Sharing documentation (opens in a new tab) technical documentation
- Undated Zero rewards documentation (opens in a new tab) technical documentation
- 2024-09-25 BitcoinOS open-sources BitSNARK v0.1 (opens in a new tab) technical and organizational primary record
- 2024-10-06 BitSNARK v0.1 README at immutable public-mainline commit (opens in a new tab) technical primary record
- 2025-02-28 BitSNARK public README at immutable v0.2 commit (opens in a new tab) technical primary record
- 2025-02-26 BitSNARK repository snapshot with 26 February 2025 Git metadata (opens in a new tab) immutable code snapshot
- 2025-02-28 BitSNARK v0.2 pinned public tree and executed build/test record (opens in a new tab) immutable code and reproducible execution record
- 2025-02-28 BitSNARK Multiplier(1000) Circom test circuit at immutable commit (opens in a new tab) code primary record
- 2025-02-28 BitSNARK hard-coded Groth16 proof and verification-key path at immutable commit (opens in a new tab) code primary record
- 2025-02-28 BitSNARK verifier-response and timeout paths at immutable commit (opens in a new tab) code primary record
- 2025-02-28 BitSNARK intended two-key locked-funds leaf and pre-signing setup at immutable commit (opens in a new tab) code primary record
- 2025-02-28 BitSNARK TLA+ transition model at immutable commit (opens in a new tab) formal-model primary record
- 2025-02-28 BitSNARK locked-funds leaf and timeout transaction templates at immutable commit (opens in a new tab) code primary record
- Undated BitSNARK decoder verification test at immutable commit (opens in a new tab) technical primary record
- Undated BIP141 — Segregated Witness consensus specification (opens in a new tab) Bitcoin consensus primary record
- Undated BIP143 — version-0 witness signature digest (opens in a new tab) Bitcoin consensus primary record
- Undated BIP341 — Taproot consensus rules and signature message (opens in a new tab) Bitcoin consensus primary record
- Undated BIP342 — Validation of Taproot Scripts (opens in a new tab) Bitcoin consensus primary record
- 2026-07-07 Bitcoin Core 31.1 release binaries and hashes (opens in a new tab) consensus implementation release record
- 2025-06 BitSNARK and Grail technical white paper (opens in a new tab) technical primary record
- Undated BitcoinOS technology page (opens in a new tab) organizational statement
- Undated BitcoinOS technical documentation (opens in a new tab) technical primary record
- 2024-01-24 BitcoinOS: Building in Layers to Unlock Bitcoin's Potential (opens in a new tab) Yago-authored organizational statement
- 2024-08-07 How We Did It: The First ZK Proof on Bitcoin — Edan Yago & Gadi Guy at Bitcoin Nashville (opens in a new tab) official video; direct Edan Yago statement
- 2025-01-29 Bitcoin Learns New Tricks: Your Portfolio's Next Move | Swiss Web3 Fest Keynote w/ Edan Yago (opens in a new tab) official video; direct Edan Yago statement
- 2025-01 Manifesto: Bringing Crypto Home To Bitcoin (opens in a new tab) organizational statement with technical qualification
- 2025-02-19 BitcoinOS Launches “Holy Grail” Bitcoin Bridge App Ahead of $BOS Presale (opens in a new tab) paid promotional article with attributed Edan Yago statement
- 2025-06-12 BitcoinOS Live! Interview with Yago | Cardano, ZK-proofs, and $BOS token pre-sale (opens in a new tab) third-party presale interview; direct Edan Yago statement
- 2025-02-16 Grail testnet bridge launch record (opens in a new tab) technical primary record
- 2025-02-27 BOS presale: Be Early to Bitcoin Again (opens in a new tab) fundraising and investor-marketing primary record
- 2025-03-20 BOS open-sources BitSNARK v0.2 (opens in a new tab) technical and organizational primary record
- 2025-04-14 Revolutionizing Bitcoin: An Exclusive Interview with Gadi Ghai, CTO of BitcoinOS (opens in a new tab) third-party interview; direct Gadi Guy statement
- 2025-04-24 BOS Token Presale Phase 2 Coming Soon — Be Early to Bitcoin Again (opens in a new tab) fundraising result and promotional primary record
- 2025-05-08 BOS Presale Phase 2 is Live (opens in a new tab) fundraising continuation primary record
- 2025-07-03 BOS Presale Maintenance Notice (opens in a new tab) fundraising migration primary record
- 2026-08-21 Origins project and backend-period index (opens in a new tab) first-party launchpad metadata retrieved at research cutoff
- 2026-08-21 Origins BOS completed backend period 3bee1d18 (opens in a new tab) first-party completed launchpad counter retrieved at research cutoff
- 2026-08-21 Origins BOS completed backend period 982bd8f6 (opens in a new tab) first-party completed launchpad counter retrieved at research cutoff
- Undated Grail Pro system architecture (opens in a new tab) technical primary record
- Undated Grail Pro technical overview (opens in a new tab) technical primary record
- Undated Grail Pro institutional integration (opens in a new tab) technical primary record
- Undated Grail Pro frontend trust model (opens in a new tab) technical primary record
- Undated Grail Pro operator deployment instructions (opens in a new tab) technical primary record
- Undated Grail Pro BTC-to-zkBTC bridging workflow (opens in a new tab) technical primary record
- 2025-09 Grail Pro: Bringing Institutional Bitcoin to DeFi (opens in a new tab) organizational and technical primary record
- 2025-03-03 BOS presale opening announcement (opens in a new tab) fundraising primary record
- 2025-10-20 BOS presale closing notice (opens in a new tab) fundraising primary record
- 2025-10-29 BOS TGE and trading announcement (opens in a new tab) fundraising primary record
- 2025-08 zkBTC institutional pilot announcement (opens in a new tab) organizational statement
- 2024-11-28 Philip DiSarro and Edan Yago bridge-trust exchange transcript (opens in a new tab) third-party transcript requiring audio preservation
- 2025-09-18 BTC OS Limited MiCA white paper (opens in a new tab) regulatory filing
- 2024-07-23 Reported final BitSNARK demonstration transaction (opens in a new tab) on-chain record
- 2024-07-31 Bitcoin rollups are closer than you think (opens in a new tab) technical reporting
- 2025-03-20 Bitcoin DeFi expansion faces fork dilemma (opens in a new tab) attributed interview
- Undated BitcoinOS team and leadership profiles (opens in a new tab) official identity source
- Undated Grail bridge frontend terms and conditions at pinned source commit (opens in a new tab) public frontend source and service terms
- 2025 Edan Yago — Consensus Hong Kong 2025 speaker profile (opens in a new tab) official event identity and portrait source
- 2025 Elan Nahari — Real-World Asset Summit 2025 (archived) (opens in a new tab) archived official event identity and portrait source
- Undated Weikeng Chen research and publication record (opens in a new tab) researcher profile
- 2024-07-24 exchange BitVM Builders Telegram group (opens in a new tab) public Telegram group containing the displayed Yago–Chen exchange
- 2024-07-24 Yago says BitcoinOS completed the mainnet demonstration (opens in a new tab) native public Telegram message
- 2024-07-24 Weikeng Chen challenges the covenant-without-OP_CAT claim (opens in a new tab) native public Telegram message
- 2024-07-24 Weikeng Chen warns Yago about the technical team's claims (opens in a new tab) native public Telegram message
- 2024-07-24 Super Testnet explains n-of-n covenant emulation and declines to vouch for BitcoinOS (opens in a new tab) native public Telegram thread
- 2024-07-24 Kevin He identifies trust assumptions and open implementation questions (opens in a new tab) native public Telegram thread
- Undated BitVM2 and bridge technical overview (opens in a new tab) technical primary record
- Undated BitVM Bridge: A Trust-Minimized Bitcoin Bridge (opens in a new tab) technical paper
- 2020-06-30 Bitcoin Covenants: Three Ways to Control the Future (opens in a new tab) technical paper
- 2026-07-13 Supply RBTC/USDT0 Liquidity (opens in a new tab) official campaign and Sovryn deposit-link record
- Undated Create a Merkl incentive campaign (opens in a new tab) technical primary record
- 2024-06-18 Yago states that Sovryn had not funded BitcoinOS and describes separate contributors and funding (opens in a new tab) direct funding and organizational statement
- 2024-06-18 Yago states that BOS funds would not come from Sovryn's treasury (opens in a new tab) direct treasury-funding statement
- 2024-06-20 Sovryn Community Call 63 — BitcoinOS funding and contributor separation statement (opens in a new tab) direct video statement
- 2024-07-02 BitcoinOS Q&A for discussion (opens in a new tab) direct statement and organizational planning record
- 2024-11-04 SIP-0083 — Sovryn as BitcoinOS contributor and BOS token launch participant (opens in a new tab) official governance and resource-allocation record
- 2024-11-07 Sovryn Community Call 66 — Sovryn described as a significant BitcoinOS participant (opens in a new tab) direct video statement
- 2026-03-27 Yago says BOS paid funds on Sovryn's behalf before year-end consolidation (opens in a new tab) direct cross-project payment statement
- 2026-03-27 Yago answers a question about Sovryn and BOS fund mingling (opens in a new tab) direct cross-project accounting statement
- 2026-08-22 retrieval DD Ethereum Safe state and owner set (opens in a new tab) on-chain indexed Safe state
- 2026-08-22 retrieval DD BNB Chain Safe state and owner set (opens in a new tab) on-chain indexed Safe state
- 2025-11-13 DD Ethereum Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-11-13 DD BNB Chain Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2026-08-22 retrieval DD Ethereum Safe multisignature transaction record (opens in a new tab) on-chain indexed execution and confirmation record
- 2026-08-22 retrieval Official BOS token address and allocation schedule (opens in a new tab) official token and allocation record
- 2026-08-22 retrieval Ethereum BOS token-owner Safe state (opens in a new tab) on-chain indexed token-administration Safe state
- 2025-10-23 Ethereum BOS token-owner Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-10-23 Inferred BOS ecosystem-allocation Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-10-23 Inferred BOS founding-allocation Safe 50db creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-10-23 Inferred BOS founding-allocation Safe 56a creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-10-23 Inferred BOS founding-allocation Safe 06D creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2026-08-22 retrieval BOS transfer ledger for the inferred ecosystem-allocation Safe (opens in a new tab) on-chain BOS transfer ledger
- 2026-08-22 retrieval BOS transfer ledger for inferred founding-allocation Safe 50db (opens in a new tab) on-chain BOS transfer ledger
- 2026-08-22 retrieval BOS transfer ledger for inferred founding-allocation Safe 56a (opens in a new tab) on-chain BOS transfer ledger
- 2026-08-22 retrieval BOS transfer ledger for inferred founding-allocation Safe 06D (opens in a new tab) on-chain BOS transfer ledger
- 2025-10-28 BOS administration Safe allocation transaction (opens in a new tab) on-chain token-allocation record
- Undated Sovryn Ethereum–Rootstock bridge mainnet configuration (opens in a new tab) official code and contract registry
- 2020-12-17 B7 funds the later DD/BOS operating key 0x509201…AbD6 (opens in a new tab) on-chain funding transaction
- 2025-10-22 0x509201…AbD6 first-funds the shared DD/BOS owner key 0x5C07…96C2 (opens in a new tab) on-chain owner-key provisioning transaction
- 2025-10-22 0x509201…AbD6 first-funds shared DD/BOS owner address e31c (opens in a new tab) on-chain owner-address provisioning transaction
- 2025-10-22 0x509201…AbD6 first-funds shared DD/BOS owner address 59c4 (opens in a new tab) on-chain owner-address provisioning transaction
- 2026-08-22 retrieval Earlier recurring-payment Safe solely controlled by 0x509201…AbD6 (opens in a new tab) on-chain indexed Safe state and payment history
- 2021-10-05 Earlier recurring-payment Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2026-08-22 retrieval DD BNB Chain multisignature transaction record (opens in a new tab) on-chain indexed execution and confirmation record
- 2025-12-01 DD sends 70 ETH to owner and approver 0x509201…AbD6 (opens in a new tab) on-chain direct payment and Safe execution
- 2026-03-30 DD sends 120,000 USDT to owner and approver 0x509201…AbD6 (opens in a new tab) on-chain direct payment and Safe execution
- 2026-08-22 state observation Official Ethereum BOS token proxy and owner read (opens in a new tab) on-chain contract state
- 2021-12-04/2022-11-04 0x509201…AbD6 USDT transfers to Sovryn's official Ethereum bridge (opens in a new tab) on-chain token-transfer history
- 2026-08-22 retrieval Earlier 0x509201…AbD6 payment-Safe execution history (opens in a new tab) on-chain indexed payment execution record
- 2025-06-19 Sovryn Origins multichain launchpad and unique-deposit-address model (opens in a new tab) first-party sale-infrastructure description
- 2025-03-03/2025-07-30 Early BOS Origins Ethereum collector BB55 (opens in a new tab) on-chain collector address record
- 2025-05-13/2026-04-27 Middle BOS Origins Ethereum collector FeD3 (opens in a new tab) on-chain collector address record
- 2025-07-10/2025-11-14 Post-maintenance BOS Origins collector 1160 (opens in a new tab) on-chain collector address record
- 2025-05-12 Early BOS deposit-gas wallet funds the later multichain deposit-gas wallet (opens in a new tab) on-chain sale-infrastructure continuity transaction
- 2025-05-13 Early BOS deposit-gas wallet funds the middle collector's deposit-gas wallet (opens in a new tab) on-chain sale-infrastructure continuity transaction
- 2025-07-09 Middle BOS deposit-gas wallet funds the later multichain deposit-gas wallet (opens in a new tab) on-chain sale-infrastructure continuity transaction
- 2025-05-09 Representative 6,000-USDT BOS buyer-to-deposit-to-collector trace (opens in a new tab) on-chain participant payment and collection trace
- 2025-05-21 Representative 100-DAI BOS buyer-to-deposit-to-collector trace (opens in a new tab) on-chain participant payment and collection trace
- 2025-08-15 Representative 50-USDC post-maintenance BOS buyer-to-deposit-to-collector trace (opens in a new tab) on-chain participant payment and collection trace
- 2025-05-13 Early BOS collector transfers USDC to the middle collector (opens in a new tab) on-chain collector-succession transaction
- 2025-05-13 Early BOS collector transfers USDT to the middle collector (opens in a new tab) on-chain collector-succession transaction
- 2025-03-05/2025-03-17 Early BOS collector relay route to Binance 14 (opens in a new tab) on-chain collector and exchange-deposit route
- 2025-05-21 Middle BOS collector transfers pooled stablecoins to operations wallet 4ad662 (opens in a new tab) on-chain collector destination route
- 2025-11-14/2026-04-27 Middle BOS collector transfers canonical assets directly to 0x509201 (opens in a new tab) on-chain collector destination route
- 2025-07-29 Later BOS collectors reuse the early Binance relay (opens in a new tab) on-chain collector destination continuity route
- 2024-09-09 0x509201 first-funds operations wallet 4ad662 (opens in a new tab) on-chain address-funding transaction
- 2025-06-03 Operations wallet 4ad662 transfers canonical stablecoins to 0x509201 (opens in a new tab) on-chain operational transfer record
- 2025-11-14 Post-maintenance BOS collector sends 204,103.50752 USDT to 0x509201 (opens in a new tab) on-chain collector destination transaction
- 2025-11-14 Post-maintenance BOS collector sends 30,056.588245 USDC to 0x509201 (opens in a new tab) on-chain collector destination transaction
- 2025-11-14 Post-maintenance BOS collector sends 3.605528140408725578 ETH to 0x509201 (opens in a new tab) on-chain collector destination transaction
- 2025-11-26 Post-maintenance BOS collector sends swept RBTC into Sovryn's Exchequer (opens in a new tab) on-chain BOS proceeds and Sovryn treasury route
- 2025-10/2026-08 retrieval BOS Community Sale vesting claim page (opens in a new tab) first-party distribution and claim record
- 2025-10-23/2026-08-22 Official Origins BOS Community Sale vesting vault (opens in a new tab) verified on-chain vesting contract and first-party registry record
- 2025-10-23 BOS Community Sale vesting vault creation transaction (opens in a new tab) on-chain deployment record
- 2026-03-17 Emergency cancellation of two BOS Community Sale schedules (opens in a new tab) on-chain vesting cancellation and recovery record
- Undated BOS collector 1160 participant deposits and onward sweep on Arbitrum (opens in a new tab) on-chain multichain sale-infrastructure record
- Undated BOS collector 1160 participant deposits on Polygon (opens in a new tab) on-chain multichain sale-infrastructure record
- 2026-08-22 retrieval 0x509201 Ethereum canonical-token source-and-use ledger (opens in a new tab) on-chain account and canonical-token history
- 2025-11-20/2025-11-25 0x509201 sends 200,000 USDT through a recurring Gemini-labeled deposit route (opens in a new tab) on-chain exchange-deposit route
- 2026-08-22 retrieval Gemini 4 exchange gateway address (opens in a new tab) public exchange-address attribution
- 2025-11-18/2025-11-21 0x509201 stablecoin routes to Kraken Hot Wallet 4 (opens in a new tab) on-chain exchange-deposit routes
- 2025-11-18/2025-11-30 0x509201 USDC routes to Coinbase 10 (opens in a new tab) on-chain exchange-deposit routes and official address metadata
- 2025-11-21 0x509201 USDC route to the official Orbiter Ethereum maker (opens in a new tab) on-chain bridge-maker route
- 2025-11-14 BOS collectors transfer canonical BNB-chain stablecoins to 0x509201 (opens in a new tab) on-chain cross-chain collector consolidation
- 2026-08-22 state observation 0x509201 BNB-chain canonical stablecoin balances and transfer histories (opens in a new tab) on-chain account state and complete canonical-token history
- 2025-05-21/2025-07-29 FeD3 BNB-chain stablecoin route through 6C250D to Binance (opens in a new tab) on-chain collector and exchange-deposit route
- 2025-05-12/2025-11-14 Cross-chain 60c Origins collector branch and cleanup into 0x509201 (opens in a new tab) on-chain participant, vesting, and cross-chain collector trace
- 2026-08-22 retrieval Manage deposits at scale (opens in a new tab) official custody architecture documentation
- 2025-03-03/2025-10-23 High-confidence BOS Origins Bitcoin collection candidate (opens in a new tab) on-chain candidate collection and rollover topology
- 2025-08-27/2025-10-23 Candidate BOS Bitcoin collector deposits into the later Exchequer terminal (opens in a new tab) on-chain common-terminal route
- 2026-08-22 retrieval Conflicting public labels around the common Bitcoin terminal (opens in a new tab) public exchange-infrastructure attribution
- 2026-08-22 retrieval Gemini crypto deposit-address workflow (opens in a new tab) official exchange deposit documentation
- 2025-12-04/2026-01-27 Three Exchequer RBTC routes reach the exact candidate-BOS Bitcoin terminal (opens in a new tab) on-chain cross-chain treasury route
- 2025-03-03/2025-07-09 Kraken XBT/USD daily OHLC benchmark for recovered BOS Bitcoin inputs (opens in a new tab) public market-price benchmark
- 2025-03-03/2025-10-22 Three high-confidence BOS Origins Cardano collector generations (opens in a new tab) on-chain candidate collection and rollover topology
- 2025-03-03/2025-08-27 Cardano BOS collectors use one relay to a Binance-labeled terminal (opens in a new tab) on-chain pooled collector and exchange route
- 2025-10-23 Post-cutover Cardano collector funds the official BOS distributor (opens in a new tab) on-chain sale-infrastructure use
- 2025-10-29/2026-08-22 Post-cutover Cardano proceeds and mint-derived BOS fund a Minswap liquidity position (opens in a new tab) on-chain sale-proceeds and liquidity route
- 2025-03-03/2025-10-22 Kraken ADA/USD daily OHLC benchmark for recovered BOS Cardano inputs (opens in a new tab) public market-price benchmark
- 2025-12-04/2026-01-20 Exchequer-origin routes reconcile to 508,947.877906 canonical USDT at DD (opens in a new tab) on-chain cross-chain source reconciliation
- 2026-01-12/2026-03-30 Exchequer-attributed DD funds reuse the BOS-linked Ethereum forwarding route (opens in a new tab) on-chain common-terminal and conservation record
- 2025-03-03/2025-10-22 Non-overlapping BOS Origins BNB Chain stablecoin roots (opens in a new tab) on-chain candidate collection topology and canonical-token ledger
Release checklist
Publication record
The public release was published only after the narrative, media, captions, hashes, redactions, evidence packet, and recovery materials passed the recorded release checklist.

