SSS DeFiβ2.0
DIALOGUE AND RECOVERY CHANNEL OPENSSS-INC-20260728

OFFICIAL SSS DEFI INCIDENT NOTICE

Dialogue and Asset Recovery Notice Regarding the July 28, 2026 SSS DeFi Exploit

SSS DeFi β2.0 was exploited on July 28, 2026 (the user Principal begins with c3dfh), resulting in a total loss of approximately US$9,204. The team has reconstructed the attack, reconciled all seven affected assets to their smallest atomic units, and traced the preparation funds and external proceeds across Ethereum, ICP, Bitcoin, BNB Chain and Solana. In the long-term interests of SSS and its users, we prefer a direct, private resolution and invite the party controlling the related accounts and addresses to contact us.

TO THE PERSON CONTROLLING THE INCIDENT ADDRESSES

We know the sequence. We still prefer dialogue.

We do not know who you are. We do know, with evidence, how the preparation funds were formed, how they entered ICP, how the CLMM exploit was executed, and where the external proceeds were last held.

Finding the vulnerability and organizing the cross-chain execution required technical ability. We recognize that ability. But exploiting the flaw and transferring assets without prior disclosure crossed the boundary of responsible security research.

SSS is an early-stage team pursuing a demanding mission: a decentralized private trading system for the AI era, built to compete as a world-class DeFi product. Early-stage status is not an excuse. We paused the system, protected user liabilities, reconstructed the incident, traced the assets and opened our work to scrutiny. The confirmed loss falls primarily on the team.

For a team committed to open development and decentralization, an exploit without disclosure is both a financial loss and a warning about the limits required by open systems. We nevertheless choose facts, transparency and dialogue over speculation or public accusation.

Contact us through an official private channel, return at least 90% of the traceable assets, and discuss the conditional bounty and written resolution below.

CONFIRMED TIMELINE AND FUND PATH

The public statement is backed by a closed evidence chain.

The following is a concise public summary. Exact transaction hashes, atomic-unit reconciliation and internal execution evidence are preserved separately.

01

Preparation funding emerged from a privacy pool

A Tornado Cash Classic 1 ETH withdrawal delivered 0.994816809494300000 ETH to a staging wallet. Public-chain attribution reaches its deterministic boundary at the zero-knowledge pool.

02

USDC was prepared and bridged to the primary ICP account

0.003000000000000000 ETH was exchanged for 5.633099 USDC. OneSec Transfer ID 6350 delivered 5.627466 USDC to the primary incident Principal.

03

The CLMM exploit sequence began

19 zero-cost Open/Burn groups and 3 USDT reassign groups were executed across positions 66-90, involving 4 related Principals and 58 successful withdrawals.

04

The external proceeds were traced to three chains

The last verified holdings were 0.12495397 BTC, 0.563294284542275878 BNB and 4.682760807 SOL. The terminal addresses remain under continuous monitoring.

19zero-cost Open/Burn groups4related Principals58successful withdrawals matched7/7affected assets reconciled
Public-chain boundary

The preparation path is deterministically traced back to a Tornado Cash Classic 1 ETH withdrawal. Tornado's zero-knowledge design prevents public-chain proof linking that withdrawal to a specific deposit or natural person. Further identification depends on service records, later contact with a regulated platform, lawful process, or voluntary communication.

PROPOSED RESOLUTION

A direct return remains the fastest and least destructive outcome.

90%+Return at least 90% of the traceable assets.
≤ 10%Conditional bounty, capped at US$1,000.
After returnNo bounty is paid before confirmed receipt and written agreement.
72 hoursInitial terms remain open for at least 72 hours after the first official public announcement and may be extended.

PRIVATE CONTACT

Start without disclosing personal identity.

OpenChat and Telegram are the preferred two-way channels. Email is accepted for initial contact or evidence intake. Use the incident ID in the first message.

Only the exact accounts and links published on this official domain are authorized SSS incident-contact channels.

OFFICIAL RETURN ADDRESSES

Use only the addresses published on this official domain.

EthereumEthereum Mainnet
0xd7c698390cb3f697De79A05a3bb38A279A8fc961
BitcoinBitcoin Mainnet
bc1qxnp93cpj49kw4ych75wzvrd5yfrxqhf7lg62qe
BNBBNB Smart Chain
0xd7c698390cb3f697De79A05a3bb38A279A8fc961
SolanaSolana Mainnet
265etz9pu9ksBJ1hGXmrEK7E2NdKH3XReKwAnbpJSVET
ICPInternet Computer
scas6-cexqz-kqczq-pwqxo-42ntx-koj7l-4esrn-ia5kb-7x2rq-yg3p7-3qeAccount ID: b477135139191acfd218f12d6b44b3c24957a033be51aeb5b238d91815820ed5Subaccount: default
ICP Account IDLegacy account identifier
b477135139191acfd218f12d6b44b3c24957a033be51aeb5b238d91815820ed5

TO WHITE-HAT RESEARCHERS, DEVELOPERS AND THE COMMUNITY

Help the official channel reach the relevant party.

SSS welcomes evidence-based criticism, responsible disclosure and practical security contributions. We appreciate the community helping this official channel reach the relevant party.

SECURITY NOTICE

SSS will never request secrets or upfront payment.

  • Never send a seed phrase or private key.
  • Never provide a wallet delegation or remote device access.
  • Never make an upfront bounty, processing or verification payment.

PAGE BOUNDARY

Static, non-custodial and independently verifiable.

This page does not connect a wallet, call a Canister or RPC, submit a form, set new cookies, or add new analytics. The published JSON and terms hash allow independent verification of the displayed terms.