OFFICIAL SSS DEFI INCIDENT NOTICE
Dialogue and Asset Recovery Notice Regarding the July 28, 2026 SSS DeFi Exploit
SSS DeFi β2.0 was exploited on July 28, 2026 (the user Principal begins with c3dfh), resulting in a total loss of approximately US$9,204. The team has reconstructed the attack, reconciled all seven affected assets to their smallest atomic units, and traced the preparation funds and external proceeds across Ethereum, ICP, Bitcoin, BNB Chain and Solana. In the long-term interests of SSS and its users, we prefer a direct, private resolution and invite the party controlling the related accounts and addresses to contact us.
TO THE PERSON CONTROLLING THE INCIDENT ADDRESSES
We know the sequence. We still prefer dialogue.
We do not know who you are. We do know, with evidence, how the preparation funds were formed, how they entered ICP, how the CLMM exploit was executed, and where the external proceeds were last held.
Finding the vulnerability and organizing the cross-chain execution required technical ability. We recognize that ability. But exploiting the flaw and transferring assets without prior disclosure crossed the boundary of responsible security research.
SSS is an early-stage team pursuing a demanding mission: a decentralized private trading system for the AI era, built to compete as a world-class DeFi product. Early-stage status is not an excuse. We paused the system, protected user liabilities, reconstructed the incident, traced the assets and opened our work to scrutiny. The confirmed loss falls primarily on the team.
For a team committed to open development and decentralization, an exploit without disclosure is both a financial loss and a warning about the limits required by open systems. We nevertheless choose facts, transparency and dialogue over speculation or public accusation.
Contact us through an official private channel, return at least 90% of the traceable assets, and discuss the conditional bounty and written resolution below.
CONFIRMED TIMELINE AND FUND PATH
The public statement is backed by a closed evidence chain.
The following is a concise public summary. Exact transaction hashes, atomic-unit reconciliation and internal execution evidence are preserved separately.
Preparation funding emerged from a privacy pool
A Tornado Cash Classic 1 ETH withdrawal delivered 0.994816809494300000 ETH to a staging wallet. Public-chain attribution reaches its deterministic boundary at the zero-knowledge pool.
USDC was prepared and bridged to the primary ICP account
0.003000000000000000 ETH was exchanged for 5.633099 USDC. OneSec Transfer ID 6350 delivered 5.627466 USDC to the primary incident Principal.
The CLMM exploit sequence began
19 zero-cost Open/Burn groups and 3 USDT reassign groups were executed across positions 66-90, involving 4 related Principals and 58 successful withdrawals.
The external proceeds were traced to three chains
The last verified holdings were 0.12495397 BTC, 0.563294284542275878 BNB and 4.682760807 SOL. The terminal addresses remain under continuous monitoring.
The preparation path is deterministically traced back to a Tornado Cash Classic 1 ETH withdrawal. Tornado's zero-knowledge design prevents public-chain proof linking that withdrawal to a specific deposit or natural person. Further identification depends on service records, later contact with a regulated platform, lawful process, or voluntary communication.
PROPOSED RESOLUTION
A direct return remains the fastest and least destructive outcome.
SSS prefers voluntary return and a written resolution. If no constructive response is received, SSS reserves the right to continue monitoring and preserving evidence, coordinate with bridges, exchanges, custodians and infrastructure providers, submit formal reports to competent authorities, and pursue civil, criminal or judicial asset-recovery remedies where available. SSS cannot bind law-enforcement authorities or promise criminal immunity.
PRIVATE CONTACT
Start without disclosing personal identity.
OpenChat and Telegram are the preferred two-way channels. Email is accepted for initial contact or evidence intake. Use the incident ID in the first message.
Only the exact accounts and links published on this official domain are authorized SSS incident-contact channels.
OFFICIAL RETURN ADDRESSES
Use only the addresses published on this official domain.
TO WHITE-HAT RESEARCHERS, DEVELOPERS AND THE COMMUNITY
Help the official channel reach the relevant party.
SSS welcomes evidence-based criticism, responsible disclosure and practical security contributions. We appreciate the community helping this official channel reach the relevant party.
SECURITY NOTICE
SSS will never request secrets or upfront payment.
- Never send a seed phrase or private key.
- Never provide a wallet delegation or remote device access.
- Never make an upfront bounty, processing or verification payment.
PAGE BOUNDARY
Static, non-custodial and independently verifiable.
This page does not connect a wallet, call a Canister or RPC, submit a form, set new cookies, or add new analytics. The published JSON and terms hash allow independent verification of the displayed terms.