Blockchain researchers say the wallet that collected funds from the recent TradeWiz drain had a prior history with the platform, offering investigators a concrete trail in a case that affected thousands of users.

Bitquery said the recipient address had funded 27 earlier trades through the same bot before roughly $459,000 in SOL, tokens, and recovered deposits was drained. The finding provides a lead, but it does not show who controlled the wallet or explain how private keys were exposed.

A prior trading history emerges

According to Bitquery’s investigation, the address that received the stolen funds was not new to TradeWiz activity. Researchers linked it to 27 previous trades carried out through the bot, suggesting the wallet had interacted with the service before the incident.

That history matters because it gives investigators more than a one-off theft address to examine. At the same time, the connection is limited: it does not prove that the same person who used the wallet as a customer also carried out the drain, nor does it resolve how access to users’ wallets was obtained.

Scale of the incident

Bitquery estimated that about 20,933 wallets were affected. The firm put the losses at approximately $459,000, including SOL, other tokens, and deposits that could be recovered by closing token accounts.

The valuation uses SOL at $120, meaning the total is an estimate rather than a final audited figure. Even so, the numbers indicate a broad incident for a trading bot service whose users were told to stop relying on certain wallet addresses after the breach.

TradeWiz response and refunds

In a security notice dated September 30, TradeWiz attributed the incident to private-key exposure tied to its SOL PVP export feature. The company instructed customers to stop using their existing SOL PVP wallet addresses and said it would fully compensate users for losses.

TradeWiz later said the first refunds had already been sent, while adding that each claim would need to be verified. The company also paused EVM services while it carried out security checks.

Its public updates outline compensation plans and security upgrades, but they do not yet fully answer which wallets were exposed, how the export function was compromised, or what changed before services were allowed to resume.

Exchange trails and the next confirmed steps

Bitquery also said it traced earlier funding linked to the wallet to withdrawals from MEXC and later transfers toward a Kucoin deposit address. Those links do not accuse either exchange of involvement in the theft, but they point to records that investigators may seek as they map the movement of funds.

For users, the most concrete next steps are the completion of reimbursements and further verification of claims. For the broader investigation, a technical explanation of the breach and clearer accounting of the exposed wallets remain the key missing pieces.

Source: news.bitcoin.com