Zunami Protocol: A Forensic Chronicle of Exploits and On-Chain Evidence
Just three days after the August 2023 breach, a transaction was dispatched directly from the Zunami Protocol Deployer to the attacker's address.
No ETH changed hands. Block 17928584, timestamped 2023-08-16 16:28:47 UTC, visible on Etherscan.

Transaction link: 0x91b41d5b5b30a941c65d5da952c4b11390f364b41cf81a1a87fba9b67b69fe22
For almost three years, this transaction sat unnoticed by the wider public.
Immediate security monitoring rapidly flagged the attack: The exploit involved flash loans and price manipulation, resulting in the loss of 1,184 ETH, which was subsequently moved through Tornado Cash. The initial analysis covered the technical vector, and the incident seemed resolved.
While the hack itself was widely reported, subsequent developments remained uncovered.
Forensic analyst NanoJS10 uncovered a trail and pursued it further.
The findings from this thread constitute more than a post-mortem; they outline a detailed case, involving specific wallet addresses, notifications to exchanges, law enforcement submissions (FBI and Interpol), and confirmation from a Coinbase Senior Director that account records are prepared for legal requests.
$2,969,000 lost over four attacks spanning 28 months, with the latest occurring in May 2025.
When evidence is preserved on a public blockchain but ignored for years, what else might have been overlooked?
Credit: NanoJS10, Zunami Protocol, Sterx
Every protocol's origin is tied to a deployer wallet—the address responsible for contract deployment, protocol upgrades, and trusted operational authority.
From a forensic standpoint, any post-exploit communication between the deployer and the attacker's address is highly unusual.
Ordinarily, a protocol exploit by external actors should not result in post-incident contact between these two parties.
On August 16, 2023, following a significant financial loss attributed to external price manipulation, the Zunami Protocol Deployer reached out to the attacker's wallet.
On that day, the deployer sent a transaction embedding a plain-text message in the transaction data to the attacker's address.
Contact Transaction: 0x91b41d5b5b30a941c65d5da952c4b11390f364b41cf81a1a87fba9b67b69fe22
Zunami Protocol Deployer: 0xe9b2B067eE106A6E518fB0552F3296d22b82b32B
2023 Attacker EOA: 0x5f4C21c9Bb73c8B4a296cC256C0cDe324dB146DF
The message stated: "We're presenting a 20% reward for the funds taken from this hack, which you can keep by returning the remaining 80%. We believe this is a fair price and it will enable all parties to come out ahead. If not, we will bring our full force to address the issue with the utmost severity of the law. We anticipate the funds' return by August 19th at 09:00 UTC. Next, we raise the reward and open it to the public."
No tokens were transferred and no contracts were called. This was a written settlement proposal, delivered from the deployer wallet directly to the attacker three days after the incident.
The specified deadline was August 19, 2023, 09:00 UTC.
After the deadline, on August 24th, the deployer performed a zero-ETH transaction to itself, before resuming standard protocol operations.
Such zero-value transactions are common for wallet management, but the sequence is notable: A direct settlement offer, a stated deadline, no visible reply, then a return to routine actions.
The blockchain record contains no public notice of failed negotiations, nor is there evidence that the reward offer was escalated as suggested.
The attempt to settle concluded without public acknowledgment.
NanoJS10 discovered this transaction years after the fact, and the significance of its message became clear only upon closer analysis.
This distinction highlights the gap between initial reporting and deeper forensic investigation.
Tracing the involved wallets yields further findings.
The deployer wallet responsible for the transaction can be linked to sterx.eth.
sterx.eth Wallet:
0xF9605D8c4c987d7Cb32D0d11FbCb8EeeB1B22D5d
Intermediary Wallet: 0x76B70FC212F688104b2ae580D82b62877BCCB2d7
According to NanoJS10's analysis, sterx.eth both funded the deployer at the outset and continued to receive funds from it during the protocol's operation. In April 2026, the deployer transferred 0.014 ETH to sterx.eth, reinforcing the conclusion that these wallets were likely operated by the same party. sterx.eth also manages zunamidao.eth.
An earlier investigation identified sterx.eth as belonging to Zunami CEO Kirill Kozlov. The wallet that engaged the attacker directly and the CEO's personal address are part of the same group, connected from launch through ongoing activity into 2026.
No official post-mortem or public discussion ever mentioned the message from the deployer to the attacker. Zunami never referenced it in their own incident reports.
The negotiation, though on-chain, remained unremarked for years—raising questions about what else could be missed on Etherscan.
143 Days Preceding the Incident
The groundwork for the August 2023 attack began months earlier.
On-chain data shows activity starting March 23, 2023, exactly 143 days before the exploit, when 15.999 ETH was sent from an OKX hot wallet to a staging address.
OKX Hot Wallet to Staging Wallet A: 0x1b315017748bf8b7aca7d58771e172e88a5d9b08a972f8f7027dc7014433b5cb
OKX Hot Wallet: 0x4E7b110335511F662FDBB01bf958A7844118c0D4
Wallet A (Staging): 0xF00d0e11AcCe1eA37658f428d947C3FFFAeaDe70
OKX, a KYC exchange, maintains identity information for its users.
Over five months, the staging address accumulated funds quietly through two exchanges.
On day 96, a Binance account transferred another 34.998 ETH.
Binance to Staging Wallet A (34.998 ETH, 2023-05-27): 0x27f5665edacc30a7bae57d27e964272087b7b9f8276c468a48b6b6fe13e653a1
Two KYC exchanges, both leaving an identity trail, funneled assets into one staging point.
Subsequently, Wallet A distributed funds to Wallet B through five transactions over the 143-day period.
Wallet B: 0x12e98c4EBD742ca9465789570e5cf4Df9EEd0Fb0
Day 46: 0.00036 ETH, likely a test transaction.
Wallet A to Wallet B (0.00036 ETH, 2023-04-07): 0x5ad68e8ae2b68b3ffc76f94dbf6933ce234b5c0f47c2f310bb7f07f744ed770a
Day 75: 0.092 ETH.
Wallet A to Wallet B (0.092 ETH, 2023-05-07): 0x2a1dc84d940feeb0253f926affe9d7a7639768c5475a2296401d1d099b111b17
Day 107: 1.41 ETH.
Wallet A to Wallet B (1.41 ETH, 2023-06-06): 0x216f1585d7e921c3fb5008a28ef8f09dadc69d214a8235cb7b7b90bd7a969af9
Day 136: 3.88 ETH.
Wallet A to Wallet B (3.88 ETH, 2023-07-07): 0x297ca310dbe55b65a3b86a3fd5a88924c8dbdfc4835bfbe936d8fb7b3ce92bba
Day 143: 5.19 ETH, one week before the hack, marking the end of the staging sequence.
Wallet A to Wallet B (5.19 ETH, 2023-08-06): 0x74454ddcdea146a6a0006acc1cef4adf9142475037f9c52ea517f7493cf05e7c
On August 13, 2023, the exploit day, Staging Wallet A continued to play a role.
Exploit-Day Link (2023-08-13 22:41:35 UTC): 0x76b70f7c6a9a58388ffa98be0ff2b68f97c05237686693c5cf1c92da29dd713f
The attacker's address sent 1,265.45 USDT to Staging Wallet A using the 0x Exchange Proxy.
2023 Attacker EOA:
0x5f4C21c9Bb73c8B4a296cC256C0cDe324dB146DF
Wallet A returned 0.687995 WETH to the attacker through the same 0x Exchange Proxy in that transaction.
**NanoJS10's assessment is that this constitutes a direct operational link between the OKX-funded staging wallet and the exploit itself.
Cumulatively, the forensic trail details a wallet funded via KYC exchange months before the attack, subsequently topped up by another KYC exchange, actively involved during the exploit.
NanoJS10's conclusion: The advanced setup and use of two centralized exchanges is incompatible with a spontaneous exploit.
Given the length and detail of preparation, does this scenario resemble opportunistic hacking?
When a multi-month staging operation directly feeds into the exploit, is "hack" the right term for what happened?
Consistent Patterns Across Multiple Incidents
There have been four distinct attacks, each using different technical approaches, but a single deployer wallet features prominently in the two most significant cases.
**Prior to the major August 2023 event, Zunami had already suffered two earlier incidents in 2023](https://github.com/NanoJS10/Zunami-protocol-Investigation-), which were acknowledged and explained._
On January 26, a swap was subject to a mempool sandwich attack, resulting in a loss exceeding $49,000.
In February, an attacker exploited price discrepancies across Zunami pools, using flash loans to mint ZLP tokens at undervalued prices and redeeming them at inflated rates, repeated thirteen times.
According to Zunami's Medium post, the February loss was $260,000.
[By March, losses had reached $309,000 across two incidents. Then came August.
The August 13, 2023 breach became the most well-known.
Flash loans struck the zETH and UZD pools on Curve, causing their pegs to collapse by 85% and 99%, respectively. The exploit's core was a flaw in the LP price calculation within the totalHoldings function, where SDT and sdtPrice were artificially increased through large swaps, letting the attacker drain assets at manipulated values.
PeckShield verified the price manipulation vector within one hour. Coverage appeared shortly after.
Nearly two years passed with little further public discussion.
On May 14, 2025, the pattern changed. No flash loans or price manipulation. Instead, the Zunami Deployer assigned admin roles to two contracts twelve seconds apart, and both were emptied by an attacker six minutes later.
Role Grant: 0x2697a6f04bb4aff65f9ce2e7a3cac8addeafc52131495ef4d1760316b5aee3b0
Zunami Protocol Deployer: 0xe9b2B067eE106A6E518fB0552F3296d22b82b32B
Attack Transaction: 0xd7ce50992b36acbc746a821a74e5600230cfe5b36cfc155841581e376f4c14d2
2025 Attacker EOA: 0x051370419b871F7C05dEE8f7134401530832e250
A total of 296,456 LP tokens were extracted in a straightforward manner: the attacker simply had admin privileges.
Twenty-six deposits to Tornado Cash followed, amounting to about 204.2 ETH, all within thirteen minutes of the drain.
The deployer wallet that contacted the 2023 attacker was the same one that assigned admin roles before the 2025 theft.
Zunami's founder, Sterx, commented two weeks after the 2025 incident: "We're investigating the exploit and considering both scenarios: a compromised deployer or malicious intent by the key holder."
He has not posted publicly since.
In Zunami's Discord, as documented by Rekt, then-CTO Mikhail Zelenin provided an alternative theory: His laptop, containing all protocol source code unencrypted, was seized at a Russian border crossing.
His suggestion: The hard drive was cloned.
He also admitted that protocol strategies were never transitioned to DAO governance as promised, due to lack of resources and developer fatigue. "I was the only developer," he said. "I made simple mistakes."
Community members were less forgiving. "You're either a thief or completely incompetent and responsible for the protocol getting hacked three times."
Four incidents, each with separate explanations, but the deployer wallet remains a central figure throughout.
With the same address linking both the 2023 attacker and the 2025 admin grants, the consistency defies coincidence.
If patterns are persuasive, what does the transactional evidence indicate?
The KYC Connection
While many analyses stopped at Tornado Cash, the trail continued.
After the August 2023 incident, the attacker's address conducted 35 consecutive Tornado Cash deposits.
Most reports end here, assuming the funds are irretrievable and untraceable.
NanoJS10 followed the trail further.
A MetaSleuth flow chart maps out the movement of funds over nearly two years, showing how assets moved from the exploit wallet through multiple intermediaries and DEXs, eventually landing at KYC exchanges.
Tracking Wallet B ultimately leads to Coinbase.
The initial transfer was recorded on November 10, 2023.
Wallet B:
0x12e98c4EBD742ca9465789570e5cf4Df9EEd0Fb0
Wallet B to Coinbase (21.354 ETH, 2023-11-10 23:39:11 UTC): 0x9e323610282c86c356be8792b864f820e86b6cc3ea2cf42ab4eeb7927d98c6e1
Receiving Coinbase Address:
0x10e3d0699b2eFa3Af238B88bbFEecc971BcCbf83
The cashout process did not end there.
Five additional withdrawal rounds took place from February 2024 to October 2025.
Each round followed a similar path: Wallet B sent funds to an intermediary, which then deposited to a Coinbase address.
16.961 ETH, 2024-02-08: 0x2aee51b7fd22c6979db0010fd9a3835bafc2d5a3efeefb1f611e71105a74fe44
Intermediary: 0x119bDFB802f7723bCDEc281e6BEc12F1A2A9F231
Coinbase Address: 0x77696bb39917C91A0c3908D577d5e322095425cA
7.461 ETH, 2024-03-25: 0xabb8c57d57f5b30dd4ecb3ac451b9a3eb13ca72431835c158d8f4a36ecfada0c
Intermediary: 0x2ad9a351b98Fd39C30DDb52D37415D0f01eF5D00
Coinbase Address: 0x95A9bd206aE52C4BA8EecFc93d18EACDd41C88CC
23.291 ETH, 2024-07-11: 0xff527b48e6eb4469af56cf1bb0eaba0d767720d928f015e1cdd1049ef1b91aaa
Intermediary: 0x2A06c43A6f9805739893C0553A0fa8A062F5B22D
Coinbase Address: 0xA9D1e08C7793af67e9d92fe308d5697FB81d3E43
4.39 ETH, 2025-03-11: 0xbd1907140754f805acf15daf8dfcb6ae740dca53b8af2ea63ef0eb285c55f2f5
Intermediary: 0x62ADe071746Cb288Ece3022F89ABd0df5Af53322
Coinbase Address: 0xb5d85CBf7cB3EE0D56b3bB207D5Fc4B82f43F511
1.773 ETH, 2025-10-05: 0x8a77cd859d68d93206e58e5e5a06b735853b4cb14cbe1a757189caaeb5fc435b
Intermediary: 0xd7ED915293dC004851f5738A080eD4e22da04293
Coinbase Address: 0xb5d85CBf7cB3EE0D56b3bB207D5Fc4B82f43F511
Cumulative total: Around 75.2 ETH over six rounds, extending across almost two years.
sterx.eth also shows direct exchange links.
In August 2020, two Binance hot wallet transfers reached sterx.eth, years prior to the exploits and staging activity.
Binance to sterx.eth (4.995 ETH, 2020-08-22): 0x4694566855ce96809a9266d9cfa64e30fea5843234089c84771757b8843e1d29
Binance to sterx.eth (12.71 ETH, 2020-08-22): 0xf46c03f33110ad986dd9ee3d9ab1ff274933d17710c736cfcbb5ee9664cf3fd0
OKX has identity records for the staging wallet funded at the very beginning of the attack timeline.
OKX to Staging Wallet A (15.999 ETH, 2023-03-23): 0x1b315017748bf8b7aca7d58771e172e88a5d9b08a972f8f7027dc7014433b5cb
By May 2, 2026, sterx.eth sent funds to a ByBit account that also received 25.2 ETH from zunamiteam.eth during the pre-exploit staging phase.

These transactions were triggered by sterx.eth through a Safe multisig, with zunamiteam.eth forwarding the funds to ByBit.
If both wallets were under unified control, this would link the deployer group and the personal wallet to the same ByBit account.
ByBit Deposit: 0xA7b7Bc3fC962614d51553829717D6e1884458039
sterx.eth via zunamiteam.eth to ByBit (22.2 ETH, 2024-05-07): 0x1f409282738219c7031ebfb679a7a956d162e591f4b5165960541da37c4fda07
sterx.eth via zunamiteam.eth to ByBit (3 ETH, 2024-05-07): 0x5cc7b5d25c652bea32cb731c1b6098d3ceda673171c3afe27c2334adac8217b3
sterx.eth to ByBit (active May 2, 2026): 0x456189d606fcade0a47221ec3e054c655d3134c3be0f0caff8843faa5512881d
ByBit can correlate that deposit address to a user account.
Obfuscation efforts persisted beyond the initial attacks. In December 2025, sterx.eth registered for Tornado Cash L1 Helper, preparing for further privacy transactions well after the August 2023 attack.
sterx.eth Tornado Cash L1 Helper Registration (December 2025): 0xbf03b63adb606901a3d6db1b7b47ba17682267cd7468f510a87c5ca18a01ef8a
This setup after the main exploits indicates ongoing concern about transactional privacy.
The Zunami Deployer was last observed active on April 26, 2026, moving SAFE tokens from zunamiteam.eth to sterx.eth. sterx.eth was last seen active May 13, 2026, sending funds to the ByBit address above.
The transactional history suggests ongoing infrastructure, not merely aftermath, with recurring addresses in every stage.
Why channel illicit gains through layers of wallets and conversions only to ultimately withdraw at a KYC exchange?
The Investigation Dossier
On May 16, 2026, a comprehensive forensic report was submitted to all identified exchanges and the FBI IC3, referencing Case ZNM-NANOJS02-INV.
Interpol was also notified with a separate filing the same day.
ByBit confirmed receipt and directed law enforcement to their compliance team.
A Senior Director at Coinbase individually reviewed the submission.
A follow-up email from Coinbase stated: “Thank you for providing the additional details regarding the Zunami Protocol exploit proceeds. We are prepared to explain the relevant transactions and provide the requested account data should law enforcement contact us regarding this case. As previously noted, they may request this information via a formal subpoena.”
Note: Coinbase’s reply was shared via PDF by NanoJS10.
Submissions to Binance, OKX, Chainalysis, and TRM Labs are still pending as of the latest update.
To date, Zunami has not issued any statement regarding the deployer-to-attacker message. No public analysis has addressed it. There was no community discussion until now.
Three weeks after the May 2025 exploit, Sterx told users the team was “considering both scenarios: a compromised deployer or malicious intent by the key holder.”
A community moderator in Thailand set a June 13th deadline for updates, threatening to file a police report if no response was received.
The deadline passed without any further update. Neither Sterx nor the Zunami Protocol account has posted since.
Yet the wallets remain active.
The deployer was last seen April 26, 2026. sterx.eth was last seen May 13, 2026.
The CTO’s hypothesis remains a cloned laptop at a Russian border checkpoint.
Administrative control was never transferred to a DAO as pledged, and protocol strategies were left unsecured.
The full forensic report is available at NanoJS10's Zunami Protocol Investigation.
Each transaction referenced herein can be independently verified on Etherscan.
While blockchain evidence alone cannot establish guilt, it can delineate a clear path, leading directly to KYC records at Binance, OKX, Coinbase, ByBit, and MEXC.
All are accessible to law enforcement through established legal processes, provided jurisdictional requirements are met.
When the forensic groundwork is complete, exchanges have responded, and reports have been filed with authorities, the question remains: what is the investigation still awaiting?
The blockchain provides a permanent, immutable record—no edits, no omissions, no delays in response.
Every transaction mentioned has been on Etherscan since its execution, publicly available to anyone who seeks it out.
NanoJS10 extended the investigation further than others.
The findings reveal a narrative that had not previously been examined: A deployer wallet sending a settlement message, a five-month staging process funded through KYC exchanges, and a cashout system operating for nearly two years and culminating at regulated platforms.
The forensic analysis is complete. All relevant exchanges have been alerted. Law enforcement filings are ongoing.
Identifiable trails rest with Binance, OKX, Coinbase, ByBit, and MEXC, all accessible through legal channels.
This is the initial Case File. More are expected to follow.
If you are a member of law enforcement, this report is ready for review.
The wallets continue to move. How long before someone acts on this information?
Get new scam files the moment we publish them — usually 2–3 emails a week.