Investigation report
The missing edge
A 26.11 SOL input and a 26.006783 SOL output are separated by 7 minutes 11 seconds and an absent public graph edge. The two signed transfers remain independently verifiable.
Analyzed
Verdict
The 26.11 SOL transfer from 5RrCL…Vbg8 is the strongest input-side counterpart to the 26.006783 SOL payout received by 6Coa63…QUtg.
The separately observed transfers align on exact asset, a 431-second interval, a 0.103217 SOL delta, source-balance behavior, immediately preceding funding, and route-deposit lifecycle. This is an evidence-backed correlation, not a directly proven cross-boundary transfer.
Route structure
The visible edges—and the missing one.
Solid edges are signed transfers · dashed edges are ranked correlations
01 · Candidate source26.11 SOL 5RrCLJ6m9HF8i7vGCDozfgxrMF1AHpJANYwD26piVbg8Observed senderAddress ↗- Observed transferSignature-matched input-side edgeProof transaction ↗
02 · Route deposit 6yrm9w2ietJQL2WAdcEng3rFKo5YeMsqUiUvnjQ6t147Observed recipientAddress ↗ - Inferred privacy boundaryRanked correlation; no graph edgeNo direct transaction
03 · Output sender 4sGeh7mzWbL4J3c9kuPCXZHV19nRKNobhzAAWV71RC4cObserved senderAddress ↗ - Observed transferSignature-matched output-side edgeProof transaction ↗
04 · Output recipient26.006783 SOL 6Coa63JdxfZoH17Vs4NzAn1DnM79kEiGoV6TUeCxQUtgObserved recipientAddress ↗
Named entities
Who appears in the route.
Attribution is shown only when supplied by the evidence record
5RrCLJ6m9HF8i7vGCDozfgxrMF1AHpJANYwD26piVbg8↗6yrm9w2ietJQL2WAdcEng3rFKo5YeMsqUiUvnjQ6t147↗4sGeh7mzWbL4J3c9kuPCXZHV19nRKNobhzAAWV71RC4c↗6Coa63JdxfZoH17Vs4NzAn1DnM79kEiGoV6TUeCxQUtg↗iGdFcQoyR2MwbXMHQskhmNsqddZ6rinsipHc4TNSdwu↗Evidence chain
Facts remain solid. Inference crosses the gap.
- observedChain fact
Observed · preceding transaction
2,469,955 DEXTER leaves the candidate source
2469955 DEXTER
The transaction and the source wallet's token balance change are directly observable. Its economic interpretation is recorded separately as a derived finding.
- derivedDerived fact
Derived · funding classification
The preceding swap yields 24.76178471 SOL
24.76178471 SOL
Instruction and balance-delta analysis classifies the preceding transaction as token-sale funding 25 seconds before the input-side transfer.
- observedChain fact
Observed · input-side transfer
26.11 SOL enters the route-deposit address
26.11 SOL
A finalized, source-signed System Program transfer moves the exact input amount. This event does not by itself identify any later output.
- inferredInference
Inferred · privacy boundary
A Houdini-style route fits the missing interval
The input and output signatures are correlated by a versioned timing, amount, and lifecycle fingerprint. There is no public transaction connecting the route deposit to the visible output sender.
- observedChain fact
Observed · unrelated dust
0.00001 SOL reaches the route deposit
0.00001 SOL
This unsigned inbound lookalike dust transfer is preserved as a chain fact and excluded from ownership and route reasoning.
- observedChain fact
Observed · unrelated dust
0.000001 SOL reaches the route deposit
0.000001 SOL
A second unsigned lookalike dust transfer is independently observed and excluded from ownership and route reasoning.
- observedChain fact
Observed · submitted output
26.006783 SOL reaches the submitted recipient
26.006783 SOL
A finalized System Program transfer from the visible sender reaches the submitted recipient. The chain proves this edge, but not its relationship to the earlier input.
- derivedDerived fact
Derived · exact comparison
431 seconds elapsed with a 0.103217 SOL delta
Integer arithmetic over the two observed transfers gives a 0.3953159709% difference from the input amount.
- observedChain fact
Observed · subsequent transfer
26.10459 SOL leaves the route-deposit address
26.10459 SOL
The route-deposit address signs a later finalized transfer. Whether this behavior belongs to a particular provider is a separate attribution question.
- derivedDerived fact
Derived · address lifecycle
The route deposit exhibits a fresh-receive-then-sweep sequence
Historical inspection found no earlier economic history before the 26.11 SOL receipt, followed by poisoning dust and a source-signed outbound sweep 519 seconds later.
- externalExternal record
External · mutable attribution
Solscan labels the sweep destination “Bybit Wallet 10”
This label was observed on 2026-08-22. It is supporting third-party attribution, not an immutable on-chain fact and not proof of route ownership.
Candidate ranking
Why the leader wins.
Deterministic evidence scores · never probabilities
Candidate 01
Near-certain input-side counterpart; the cross-boundary relationship remains inferred.
asset.same-token
Both independently observed transfers move native SOL.
route.elapsed-time
The output follows the input by exactly 431 seconds, inside the versioned route window.
route.amount-conservation
The output is 0.103217 SOL below the input, a 0.3953159709% difference.
source.balance-behavior
After the input and network fee, the source retains 0.053558881 SOL from a 26.163570241 SOL pre-transfer balance.
source.preceding-funding
A 2,469,955 DEXTER sale produces 24.76178471 SOL for the source 25 seconds before the input transfer.
intermediate.freshness
Historical inspection found no economic history for the route deposit before the candidate input.
intermediate.lifecycle
The fresh receipt followed by a source-signed near-full sweep matches the versioned single-use route-deposit pattern.
intermediate.address-poisoning
Two unsigned lookalike dust transfers are excluded from ownership and route scoring.
attribution.sweep-destination
Solscan labeled the later sweep destination “Bybit Wallet 10” when observed; the mutable label does not establish route ownership.
Reproduce the reasoning
Methodology
- 01
Search top-level native SOL transfers between 26 and 30 SOL in the 30 minutes preceding the submitted output.
- 02
Re-read candidate transactions and wallet context, preserving exact lamports, signatures, balances, and timestamps.
- 03
Score timing, same-asset amount conservation, source funding, source balance behavior, address freshness, and subsequent lifecycle with a versioned fingerprint.
- 04
Retain observed transfers as direct facts; represent the absent input-to-output edge only as an inferred relationship.
Limits on this finding
- The public chain contains no direct transaction from the route deposit to the visible output sender.
- Near-certain is an evidence classification, not cryptographic proof or a probability estimate.
- Provider or exchange control is not inferred solely from transfer behavior; mutable third-party labels are disclosed separately.
- This frozen public case records evidence available at analysis version 1.1.0 and does not silently refresh mutable labels.