---
title: Cases — BlockEye
description: GeoTrace in Action: recent public incidents and enforcement actions, alongside GeoTrace's geographic inference for the addresses involved.
canonical_url: https://www.blockeye.ai/cases.html
last_updated: 2026-08-25
---

# Cases — GeoTrace in Action

Recent incidents and enforcement actions, alongside GeoTrace's geographic inference for the addresses involved.

## Validation

- 94% overall accuracy, across 30+ countries and regions.
- 91% third-party cross-validation, jointly verified with a globally renowned blockchain KYC institution, spanning several hundred times as many addresses.
- VPN-bypass true-location recovery: pinpoints a user's true country or region even behind VPN masking.

## Phishing drainer · Aug 2026

On August 13, a victim searching for Hyperliquid clicked a sponsored phishing ad on Google and signed a permit approval; 550,000 USDC was drained in a single transaction split across three wallets (Arbitrum).

- Address: [0x6fe314fd4cf845f35fc461ed98e2fb8d9356b566](https://arbitrum.blockscout.com/address/0x6fe314fd4cf845f35fc461ed98e2fb8d9356b566) (Arbitrum)
- GeoTrace inference: Europe 45%; Hong Kong, China 34%.
- The attacker most likely operates from Europe, while deposits and withdrawals may have passed through accounts related to Hong Kong, China. Joint inference over a group of wallets linked to the attacker.
- Source: [X](https://x.com/bbmiumiuu/status/2087937765900161467)

## USM exploiter · Aug 2026

On August 10, an attacker exploited a pricing flaw in USM's redemption function, splitting the redemption into 64 small transactions to steal ~70.83 ETH (~$136K).

- Address: [0xb92b2E47680c89DA8f951B8963ef469f461a50Fc](https://dashboard.misttrack.io/risk/ETH/0xb92b2E47680c89DA8f951B8963ef469f461a50Fc) (Ethereum)
- GeoTrace inference: Turkey 30%. Iran ranks second at 19%. Joint inference over a cluster of wallets controlled by the attacker.
- Source: [SlowMist](https://x.com/SlowMist_Team/status/2086644725143183639)

## Drift exploiter · Jul 2026

On July 23, the Drift Protocol exploiter moved 23,095 ETH (~$44M) to Tornado Cash after months of dormancy.

- Address: [0xf8B4dA248CbfE73ff4B827fa8E25E4f94F561d26](https://dashboard.misttrack.io/risk/ETH/0xf8B4dA248CbfE73ff4B827fa8E25E4f94F561d26) (Ethereum)
- GeoTrace inference: early — South Korea 72%; recent — Cambodia 51%.
- Source: [Cryptopolitan](https://www.cryptopolitan.com/285m-drift-hacker-funds-after-months/)

## US DOJ seizure · Jul 2026

U.S. authorities froze this address holding proceeds of a pig-butchering scam (D.D.C. Civ. No. 26-2644).

- Address: [0xf322a3328f617b9f3d44a088373d1106b6c5e97e](https://dashboard.misttrack.io/risk/ETH/0xf322a3328f617b9f3d44a088373d1106b6c5e97e) (Ethereum)
- GeoTrace inference: Cambodia 99%.
- Source: [U.S. Attorney's Office, D.C.](https://www.justice.gov/usao-dc/pr/investigations-cryptocurrency-scams-result-seizure-more-25-million)

## Jaredfromsubway · Jun 2026

Jaredfromsubway, Ethereum's most notorious MEV sandwich bot, was drained of ~$7.5M in a honeypot exploit.

- Address: [0x3e37f4a10d771ba9de44b6d301410b1bedea65d0](https://dashboard.misttrack.io/risk/ETH/0x3e37f4a10d771ba9de44b6d301410b1bedea65d0) (Ethereum)
- GeoTrace inference: Ukraine 18%. Russia, Ukraine & Eastern Europe combined: 44%, based on joint inference over a set of wallets controlled by the hacker.
- Source: [Chainalysis](https://www.chainalysis.com/blog/sandwich-attack-jaredfromsubway-hack/)

Back to [BlockEye home](https://www.blockeye.ai/). See also [GeoTrace product](https://www.blockeye.ai/product.html).
