Four Minutes of scnSOL That Nobody Called an Incident

Series ─ Crypto Memoirs

Hello, hello! Detective Bit-Taro Nyan here.

I went digging through four-year-old material and found almost all of it dead links. This is written from whatever is still readable 😇

Right, let’s get into it.

At 06:30 UTC on June 15, 2022, the price of a Solana token called scnSOL broke. It’s a receipt: you stake SOL, you get one of these back.

It started with a single swap. A holder sent 20,000 scnSOL — around $600,000 at the rate that day — through a swap. What came back was 197 SOL. Socean wrote it up as “a 98% loss”※1.

The troublesome part is that the broken price propagated somewhere else. Solend, a lending venue, used that price to decide what the scnSOL it held was worth as collateral. If collateral gets cheap, the people who borrowed against it get liquidated.

That is exactly what happened. The largest liquidation came 39 seconds after the swap. Counting through until the small ones stopped, four minutes and twenty seconds※2.

Of all the collateral that was taken, 99.5% sits in a single transaction※3※4. Whoever took it turned the scnSOL back into SOL and sent it to FTX※5.

Four years have gone by. Let’s take the public record and work back through what happened that day.

The entrance was a button on the official site#

Socean, which issued scnSOL, had an instant-unstake button on its site. It turns what you deposited straight back into SOL. What it actually does is a swap: it throws scnSOL into a pool on an exchange (an AMM) and takes SOL back.

That destination was fixed to the Orca pool that had the deepest liquidity when it launched — written directly into the code※1. Liquidity here means the money a pool holds so that it can take the other side of a swap.

A single destination isn’t a problem in itself, as long as that pool has enough liquidity. Throw in a large amount and it can absorb it.

The problem was that Orca’s pool did not have enough liquidity. The reason was dispersion. scnSOL had since started trading on Saber and Crema as well, and the liquidity was split across three places. Orca alone couldn’t absorb a large amount.

The button on the site throws to Orca regardless. Split the same order across three venues and the amount landing in each is smaller. The price moves less. The button had no such capability.

Socean itself lists, as the first of its preventive measures, switching to a new site that routes through an aggregator※1.

For what it’s worth, I couldn’t find a figure for how much liquidity that Orca pool actually held at the moment of the incident※6. That it wasn’t enough follows from the result; how far short it fell, I can’t say.

A holder pushed a large amount of scnSOL into the Orca pool. This is the swap from the opening — the one that got 197 SOL back※1.

Whether it went through the button on the site isn’t settled. Socean itself writes that it can’t tell whether the UI was used, only that it probably was※1.

That the destination was hardcoded came out five days later, in Socean’s postmortem.

Socean concluded it was an accident, on the grounds that nobody would take a loss like that on purpose※1. That’s the assessment of the party involved.

The people who came to fix it carried the distortion along#

When a pool is badly distorted, arbitrage moves in. Six seconds after the swap, several bots started going around Orca, Saber and Crema※7.

Arbitrage is, you know, the act of fixing distortion. Buy where it’s cheap, sell where it’s expensive. The prices even out. Nothing wrong is being done.

But scnSOL bought cheap doesn’t become profit until it’s sold somewhere. The place to sell is the pool next door, where the price is still high. Sell there and scnSOL piles up in that pool while SOL drains out of it. The same thing as the opening swap, happening one pool over.

The distortion didn’t disappear, it moved. It ended up happening in Saber’s scnSOL/SOL pool too.

How the distortion that started in Orca reached Saber’s pool is where the sources differ.

ora studio puts it this way. A first bot arbitraged, and as a result the price of a different Orca pool (scnSOL/USDC) distorted. A second bot then arbitraged, and this time the price of Saber’s scnSOL/SOL distorted※8.

sanny writes that this second bot “performs arbitrage on the scnSOL-USDC pool”※7. Same address, different pool.

Either one of them is wrong, or that bot was working several pools at once and the two write-ups each covered a different one. From the outside I couldn’t settle it.

The two accounts agree that Saber’s scnSOL/SOL price did in fact distort. What doesn’t line up is where the second bot was trading, and that alone.

What Solend was watching was the pool next door#

Solend (it goes by Save now) used a Switchboard feed for the price of scnSOL. Switchboard is an outside service that collects prices from on-chain and publishes them — an oracle, in other words. Solend didn’t measure what scnSOL was worth itself; it took the number from here.

And what that feed took its price from, at the time, was Saber’s scnSOL/SOL pool and nothing else※9.

When the price moves on Saber, Solend’s price follows within seconds※8. So seconds after Saber distorted, scnSOL that had been deposited started being treated as collateral worth far less than it really was.

Save’s documentation still says this in its risk section: that the oracles may report incorrect prices, and that this can cause wrongful liquidations※10. I can’t confirm the same sentence was there in June 2022. But what it describes is precisely what happened that day.

The Solend integration guide Socean published five months before the incident also lists “oracle mispricing” as one of the liquidation risks. The oracle it names, though, is Pyth※9. The one actually publishing the price of scnSOL that day was Switchboard.

The four minutes and twenty seconds the collateral looked cheap#

Once collateral looks cheap, it’s first come first served. Anyone can run a liquidation on Solend.

Liquidating means paying off the borrower’s debt on their behalf and receiving their collateral at a discount in exchange. The discount is what the person who paid keeps. It’s profitable, so people race for it.

I went through the blocks end to end. During the window when the price was distorted, transactions touching the account where Solend holds scnSOL (the reserve) come to 1,158 successful and 2,329 failed※4.

Those 1,158 include a lot that merely touched it. Ones that came only to refresh the price, ones that read this reserve incidentally while handling another asset. Nothing to do with liquidation.

I haven’t classified the 2,329 failures. I assume they’re the ones that lost the race, but I didn’t go that far.

Pulling out only the successful ones where scnSOL actually left the reserve gives 169※4. Of those, 167 are liquidations and 2 are ordinary withdrawals. The scnSOL that left comes to 59,723 tokens.

Of that, 59,404 — 99.5% of the whole — is in a single transaction※3※4. Add up the remaining 168 and you get 319 tokens.

Not a cascade, a single point. Eight addresses executed liquidations, and one of them took 99.5% while the other seven split 0.5% between them※4.

The one who took that transaction moved the scnSOL to another address, unstaked it back into SOL through Socean, and sent it to FTX※5.

The one account that took 99.5%#

The seven that didn’t take the 99.5% were all bots that had been running for years※11. The oldest goes back to August 2021, the newest to March 2022. Signed transaction counts range from 1,200 at the low end to over 17 million at the high end. One of them is still running today, as I write this. People who happened to be passing that day and picked up what spilled.

The account that took the 99.5% was shaped differently.

Every transaction this account signed falls inside the 28 days from May 26 to June 22, 2022※11. Not one before, not one after. It woke up 20 days before the incident and went silent 7 days after.

An account that lives 28 days sounds like a burner wallet. It was the opposite. In those 28 days it signed 735,000 transactions. Twenty-six thousand a day. Short-lived, and working furiously.

You can see where the money came from too. The first thing to arrive in this account was 5 SOL from an FTX hot wallet — seed money to get an account moving※12.

After that, this happened※12.

  • June 12, 06:07 100 SOL from FTX
  • June 12, 06:09 9,900 SOL from FTX

10,000 SOL in total. The date is three days before the incident.

And on the day, what this account paid in the largest liquidation was 9,989.998 wSOL (SOL in token form)※3.

What went in and what got spent are almost the same. Which means this account received just enough to run that liquidation, three days beforehand.

Six days later, a report came out in English#

Six days after the incident, ora studio (@oralabs_) published an analysis thread※8. It opens by saying that with the market’s attention on the Celsius and Three Arrows Capital (3AC) drama, nobody had been looking at this.

One swap → a chain of arbitrage → liquidation. In that order, with the amounts each bot took. Addresses included.

Two months later sanny published a piece with a second-by-second timeline※7. As far as I can tell it’s still the most complete third-party record of this.

Four and a half months later, the same shape repeats#

On November 2, 2022, Solend took on bad debt from an oracle manipulation involving USDH※13.

The technical analysis says what got targeted was “sourcing prices only through a Switchboard oracle from a Saber pool”※13. The same shape that was laid bare with scnSOL in June.

It isn’t the same place, though. What was targeted in November was the USDH feed; what broke in June was the scnSOL feed. Different feeds, the same shape. And the November analysis doesn’t mention the June incident at all※13.

For November, DAO proposals passed and affected users were compensated※13. For June, I couldn’t find any such record.

The stage is still the same account#

The scnSOL mint — the account that issues the token — is still alive.

Socean became Sanctum, and scnSOL became INF (Sanctum Infinity). The mint address is unchanged. The Solend scnSOL reserve where all this played out is still running, as the same account, as the INF reserve※14.

Only the CoinGecko ID written in Solend’s config file is still socean-staked-sol. Time has stopped in that one field※14.

Looking into it, the Switchboard feed that reserve references now is SOL_USD — the same one Solend’s SOL reserve uses. At least this reserve is no longer looking at an AMM-derived scnSOL/SOL feed※14.

But I couldn’t pin down when it changed. Right after June, after November, or later still. I found no way to trace it backwards from outside.

Did somebody set this up?#

I’ll confess that at the time I didn’t think this was a big deal. Just a whale fumbling a swap, I figured. Throw 20,000 tokens in at once and the price breaks.

Socean’s assessment comes to the same thing in the end. Nobody would willingly take a 98% loss, so it was an accident※1.

What changed my mind was seeing the Solend liquidations.

The price falls, collateral goes, somebody carries it off. For a story about one person fumbling, what follows is a little too well made.

That big swap — was it fired to make the liquidation happen? That’s where I started to doubt.

Let’s lay out the numbers.

What was thrown away. The 20,000 scnSOL that went into the swap was roughly $600,000 at the rate that day. The 197 SOL that came back was about $5,500 at that day’s SOL price. Net, about $594,000 discarded※15.

What was picked up. The person who took the largest liquidation paid 9,990 wSOL (about $278,000), received 59,404 scnSOL, and unstaked it back into 62,268 SOL (about $1,737,000). Net, about $1,458,000※15.

If the same person did both, they paid $594,000 and took $1,458,000. Around $870,000 left over.

So “a 98% loss” was an amount that also works as the price of breaking the price. Break the pool or the oracle doesn’t move. The oracle doesn’t move or the collateral doesn’t get cheap. Cost of breaking it: $594,000. Collateral available: $1,458,000. The difference is comfortably positive.

Socean’s reasoning only holds if the person who swapped didn’t take the liquidation.

Whether they did, I can’t tell directly. The only handle is what kind of account it was that executed the liquidation.

An account funded with 10,000 SOL three days earlier, gone in 28 days. At the very least, that isn’t the shape of somebody who happened to be passing.

So — was it the same person as the one who swapped? That’s where the thread ran out.

The two addresses have never once appeared together in the same transaction※16. The swapping address signed 247 transactions across five years, from November 2021 to June 2026 — it looks like an ordinary wallet※11. No contact with the FTX hot wallet either※16.

On-chain, there is nothing tying these two together.

Four years of reading, and what I’m left holding is these four things.

  • How the site was wired. The unstake destination stayed pinned to Orca
  • Arbitrage. Bots that came to fix a distorted pool carried the distortion next door
  • The oracle. The price came from that one pool next door
  • Liquidation. The collateral looked cheap, so liquidations anyone could run got run

The second is a bot’s day job. People who came to fix a distortion, and fixing it isn’t wrong in itself. The third isn’t even something anybody did — where to take the price from had simply been decided in advance. The fourth is behaviour exactly as documented.

That leaves the first. Putting 20,000 tokens through that button. This is the only one a person decided to do.

What follows is speculation. I don’t think that swap was an accident.

I think so because reversing the order makes everything connect.

The starting point was probably the liquidation end. Which feed a Solend reserve takes its collateral price from is readable from outside. Look at the published config, then go and read that feed’s account※14. And what that feed was watching at the time was one Saber pool※9. The collateral price can be moved with that single pool. If you were going to notice something, this is where.

So why not just hit Saber directly? Because you can’t. Dumping a large amount into the scnSOL/SOL pool is too naked. It’s the exact thing a person who wants to distort a price would do.

Which brings us to Orca. The unstake button on Socean’s official site was pinned to one Orca pool※1. The same thing becomes possible wearing the face of “I used the site.”

Break Orca and the distortion moves next door. Arbitrage enters a distorted pool, buying cheap and selling dear. On this day the bots started moving six seconds after the swap※7. Leave it alone and it reaches Saber.

And here is the part that does the most work. A swap sent through the official button looks, from the outside, like somebody who screwed up. What’s left behind is a record of $600,000 turning into 197 SOL.

Which is what happened. The postmortem concluded it was an accident, on the grounds that nobody would willingly take a 98% loss. And what got named as the cause there was their own site, the one with the hardcoded destination※1.

I wrote earlier that the $594,000 was the price of breaking the price. There’s one more thing it buys. Looking like an accident.

That said, nowhere in the public record is there anything showing it. Just as you can’t prove nobody intended it, I can’t prove anybody did.

Afterword#

Did somebody set this up? Four years of records later, I still can’t say. What I could read goes as far as: setting it up, using public information, would have paid.

The wiring was sloppy. Arbitrage moved in. The price came from a single source. Liquidations ran. That’s the whole list.

That’s all it took, and the people who had posted collateral lost it, and it hasn’t come back.

Come to think of it, this was also the first time I ever joined the voice chat on a Discord I was living in back then. I’d been a text-only person until that point, so it surprised people. What I was chasing was whether this was a set-up or just a mistake.

This one isn’t listed on any hack timeline or incident roundup I checked※17. I couldn’t find a record written in Japanese either※6.

What remains is two pieces written in English, six days and two months after, and the record on the chain.

People lost collateral, and that hasn’t been returned. Even so, this thing never got a name. It’s not quite that it was forgotten. It never entered anyone’s memory in the first place.

An incident that didn’t get written down anywhere still doesn’t become an incident that didn’t happen.

And now, a verse.

A whale takes a loss —
and standing just beyond it,
a human shadow

And with that, I’ll take my leave.


※1 Socean (scnSOL) official postmortem, Update on 15/6/22 scnSOL mispricing (June 20, 2022). 20,000 scnSOL (about $600,000) became 197 SOL, which the postmortem calls “a 98% loss.” As the cause it names, itself, that instant unstake’s destination was pinned to Orca’s scnSOL/SOL pool and hardcoded, while liquidity had already spread to Saber and Crema. It judges the swap unintentional on the basis that “we don’t think anyone would willingly take a 98% loss.” Three preventive measures are listed (a new site routing through the Jupiter aggregator, consolidating scnSOL/SOL liquidity into a single AMM, and working with Switchboard on multiple sources). There is no mention of liquidation counts, total losses, or compensation. It states that liquidations also occurred on Apricot Finance, without giving their scale.

※2 The event was at 06:30:16 UTC on June 15, 2022 (15:30 JST the same day; 23:30 PDT on June 14 on the US west coast). ※7 states the main action fit within 40 seconds. The liquidations verifiable on-chain span 06:30:55–06:35:15, four minutes twenty seconds (the final 14 are all dust, under 0.04 scnSOL each). The largest single one (※3) was 39 seconds after the swap.

※3 The largest liquidation transaction, 4rGqSMj3L87eQrki5WjFTA5o2fpoESdbaMUBodCYUt2FDGT4XXht5yPyUBUhGWVttCLXFQLBMe5P7oaTuVyPirUy (Solscan / Orb, both still open as of August 2026). Slot 137606378 / blockTime 1655274655 (2022-06-15 06:30:55 UTC), Solend’s Liquidate Obligation and Redeem Reserve Collateral. Signer Fx59AskDVQGxkNEUzn3wfD6GDghCLj3qNUnKrDvDLRmY paid 9,989.998 wSOL and received 59,404.496 scnSOL (collateral plus a 5% liquidation bonus). The obligation liquidated was Bx1TDJZCbqExmcs4tJbGQUhzyECdCZW9m4xXuRSJBwWs, owned by 6v8sRF16obGjn2wC5zk9Hsz1B87D1NiUZ7h5M9JHVqxU. All of this was read directly over RPC and verified. Open it in an explorer today and the token received shows as INF, not scnSOL. The mint address is unchanged and that token became INF (※14). On Orb, the cscnSOL collateral appears as a raw address, AFq1...rzoR.

※4 Verified by fetching all 501 slots from 137606330 to 137606830 (06:30:11–06:36:09 UTC), of which 109 slots are missing. Transactions including the reserve DUExYJG5... in accountKeys: 1,158 successful, 2,329 failed. Of those, 169 successful transactions actually decreased scnSOL in the reserve — 167 Liquidate and 2 Redeem Reserve Collateral. Total scnSOL out: 59,723.1020, of which the single transaction in ※3 accounts for 59,404.4960 (99.467%). The remaining 168 total 318.606, the largest being 37.4455, and 94 of them are under 1 token. Eight addresses executed them: Fx59Ask... 1 tx / 59,404.4960, F4q2bm6... 74 / 171.2970, 4FvmYJb... 20 / 78.1522, HCMRVfb... 63 / 47.6852, 8sg4tRF... 1 / 21.4708, and three further addresses totalling 10 tx / 0.0008. The last Liquidate was at 06:35:15; the final transaction (06:35:41) is a Redeem. For the 2,329 failures I only counted them; I did not classify the reasons.

※5 Traced per ※7 and ※8. Fx59Ask... moved 59,405 scnSOL to another address, Ae9..., unstaked it through Socean back into 62,268 SOL, and sent it to FTX (6ZRCB7AAqGre6c72PRz3MHLC73VMYvJ8bi9KHf1HFpNk). Deducting the 9,990 wSOL paid (verified over RPC in ※3) leaves roughly 52,278 SOL.

※6 Things that remain unknown. (a) An official Solend statement about the June incident — not in their blog, Medium, docs or any coverage I could find. (b) Likewise an official Switchboard statement. Socean writes only that it is “pushing for multiple sources”; I couldn’t reach a record of what actually changed or when. (c) The identity of the person who did the large unstake, what became of them, and whether they were compensated. (d) Whether the liquidated borrowers were compensated — the only owner I could identify on-chain is the one in ※3, and I didn’t pursue the others. (e) The scale of the Apricot Finance liquidations named in Socean’s postmortem, and any official statement from them. (f) The exact depth of the Orca / Saber / Crema pools at the time of the incident. (g) Any Japanese-language record covering this incident — I couldn’t find one within the range I searched.

※7 sanny, Into the MEV Arena - Solana’s Dark Forest (August 12, 2022). The most complete third-party record of this incident. It gives a second-by-second timeline: at 23:30:16 PDT whale 7pX puts 20,000 scnSOL into Orca’s scnSOL-SOL v2, at 23:30:22 bot G6E enters, at 23:30:26 44P, at 23:30:31 ecE. Estimated bot profits: G6E about $25k, 44P about $400k, ecE about $46k, and Fx5 $1.5M at the time of the incident, $2.2M as of that article’s writing (August 2022). Note that for 44P this article says it “performs arbitrage on scnSOL-USDC pool,” which conflicts with ※8’s account of it wrecking Saber’s scnSOL-SOL. On pool depth it says “under $10,000,” but that is an August 2022 figure, not one from the time of the incident.

※8 ora studio (@oralabs_) analysis thread, 17:41 UTC, June 22, 2022. 136 likes / 29 reposts. It opens: “Amidst the drama around Celsius, 3AC, Solend and a massive market drawdown, one of the strangest Solana MEV instances went fairly unnoticed.” The sequence it lays out: whale 7pX throws 20k scnSOL into Orca and gets 200 SOL → bot G6E arbitrages it back but wrecks Orca’s scnSOL-USDC → bot 44P arbitrages that back but wrecks Saber’s scnSOL-SOL → bot Fx5 pulls 52k SOL out through Solend liquidations. On the oracle it says Solend used Switchboard, and that the oracle depended on the aforementioned liquidity pool; that when the pool was dumped on, it was reflected in the oracle price within seconds, making collateral look far cheaper than moments before. The “40 seconds” figure is from ※7; this thread gives no timings in seconds.

※9 ※7’s article states explicitly: “at the time of the incident, Switchboard relied solely on Saber’s pool.” The Solend x Socean: A Guide to Do More with your scnSOL that Socean published five months before the incident (January 2022) lists “oracle mispricing” as one of three liquidation-risk categories, but the oracle it names there is Pyth.

※10 Save (formerly Solend) official documentation, Risks (read August 2026). “Solend relies on Pyth and Switchboard for their price feeds to power liquidations. There is a risk that these oracles report incorrect prices, causing wrongful liquidations.” This is the current wording; I have not confirmed the same text was present in June 2022. The Switchboard v2 Guide has recommended settings and an example mixing CEX and DEX sources, but no explicit warning against using a single AMM as a source, and no minimum source count.

※11 First, last and count of transactions signed by each address were aggregated on Dune (solana.transactions, matching on signer), run August 8, 2026. Fx59Ask..., which took the largest liquidation, has 735,671 transactions between 2022-05-26 15:02:40 and 2022-06-22 13:10:45, with not a single signature outside that range. The other seven: F4q2bm6... (2021-08-12 to 2026-08-08, 17,241,851), HCMRVfb... (2022-03-15 to 2025-10-30, 14,306,064), 8sg4tRF... (2022-02-24 to 2024-07-04, 966,221), 4FvmYJb... (2021-10-19 to 2026-02-24, 799,604), BdxkPBX... (2021-11-25 to 2024-12-18, 110,099), JDHt3bH... (2022-05-10 to 2022-08-20, 4,675), 6zL9HPR... (2022-03-21 to 2025-01-21, 1,215). The swap origin 7pXgZdR9eSwanbojvFjReMNqcSJWzTe2TkLq9c125UU (the swap being 22cmP7My..., releasing 20,000.68 scnSOL at 06:30:16) has 247 transactions between 2021-11-13 and 2026-06-08. Note that “last” here means the last date it signed; the address can still appear in other people’s transactions after that.

※12 Deposits into Fx59Ask... were extracted on Dune (solana.account_activity × solana.transactions). Deposits signed by the FTX hot wallet 6ZRCB7AAqGre6c72PRz3MHLC73VMYvJ8bi9KHf1HFpNk are: 5 SOL at 2022-05-26 15:02:19 (balance 5), 100 SOL at 2022-06-12 06:07:19 (balance 101.60), 9,900 SOL at 06:09:51 (balance 10,001.70), and — after the incident — 5,000 SOL at 2022-06-15 18:16:45 (balance 5,007.52). That 6ZRCB... signed 16,083,956 transactions between 2020-10-03 and 2025-03-02; it is an exchange-side hot wallet, not an individual’s deposit account. So “it came out of FTX” is as far as this goes; it does not identify the sender. Also, a bot signing 735,000 transactions in 28 days topping up its working capital is ordinary behaviour, and the 10,000 SOL deposit cannot on its own be treated as evidence of preparation. The “sent it to FTX” in ※5 comes from the tracing in ※7 and ※8; I examined ten deposits of over 10,000 SOL that entered 6ZRCB... that day, all of which were FTX’s own internal movements, so I have no independent confirmation of that route.

※13 In the USDH oracle attack of November 2, 2022, Solend booked $1.26M of bad debt (CoinDesk). Ackee writes: “Solend’s vulnerability in this exploit was that it was looking for price updates only using the Switchboard oracle from Saber pool, making the price feed prone to manipulation.” That article makes no mention of the June scnSOL incident. On compensation it says “The Solend DAO passed proposals SLND6 and SLND5 to compensate affected users.” (Helius states the bad debt was absorbed by the treasury; I haven’t reconciled the two.) The November feed was USDH; what broke in June was the scnSOL feed — a different aggregator.

※14 Solend’s public config API (retrieved August 2026). DUExYJG5sc1SQdMMdq6LdUYW9ULXbo2fFFTbedywgjNN, the scnSOL reserve at the time, is currently running under the symbol INF, with the same mint as during the incident, 5oVNBeEEQvYi1cX3ir8Dx5n1P7pdxydbGF2X4TxVusJm. The coingeckoID is still socean-staked-sol, but that is a field in Solend’s own config file and says nothing about how the token is registered on CoinGecko today. The switchboardOracle is GvDMxPzN1sCj7L26YDK2HnMRXEQmQ2aemov8YBtPS7vR; decoding the account directly gives the feed name SOL_USD, identical to the one Solend’s SOL reserve uses. What I could confirm goes as far as “this reserve is not looking at an AMM-derived feed.” I did not check whether the old scnSOL/SOL aggregator still exists on the Switchboard side, and I could not pin down when the change happened.

※15 All conversions use the SOL price at 2022-06-15 06:30 UTC of $27.90 (DefiLlama, coingecko:solana, timestamp 1655274611). What was thrown away: the postmortem in ※1 puts the 20,000 scnSOL that went into the swap at “about $600,000” (1 scnSOL ≈ $30 ≈ 1.075 SOL). The 197 SOL received is $5,497. The difference is about $594,500, broadly consistent with the postmortem’s “98% loss.” What was picked up: the 9,989.998 wSOL paid in the liquidation transaction in ※3 is $278,721, and the 59,404.496 scnSOL received, turned back into 62,268 SOL as traced in ※5, is $1,737,255. The difference is about $1,458,534, broadly in line with sanny’s contemporaneous $1.5M estimate in ※7. There is no evidence the two are the same person. The swap origin and the largest liquidator are different addresses, and I have not confirmed any flow of funds connecting them. Also, much of the $594,500 thrown away went to the three arbitrage bots (totalling $471k by ※7’s estimate) and to the pool’s liquidity providers; that is a separate ledger from the liquidator’s take. What is being compared here is “what it cost to break it” against “what could be taken because it broke” — not one person’s profit and loss.

※16 The number of times Fx59Ask... and 7pXgZdR... appear together in the same transaction is zero (Dune, matching tx_id in solana.account_activity). 7pXgZdR... and 6ZRCB... (the FTX hot wallet) likewise never appear together. Fx59Ask... and 6ZRCB... appear together in six transactions: the four deposits in ※12, plus two that don’t move the balance. Not appearing together is not proof of being different people. Route funds through an exchange and the on-chain line is cut.

※17 Neither Helius: Solana Hacks, Bugs, and Exploits, Ackee Blockchain, nor web3isgoinggreat has an entry for the June scnSOL incident (all three carry the November USDH one). Switchboard Wrap Up 2022 mentions neither this incident nor the single-source feed problem. I am not using their absence from these three to mean no record exists anywhere. Note also that on June 19–20, 2022 a separate Solend matter blew up (the SLND1 / SLND2 governance row over emergency powers against a whale account), and searching in Japanese turns up almost nothing but that. It is an entirely different incident.

Related posts

Comments

Comments appear after approval. Name is optional.