Key Highlights
- Bitquery found that Tradewiz bot activity stopped 41 minutes into the main $SOL drain, while about 73% of the stolen funds moved afterward.
- Tradewiz attributed the incident to private-key exposure linked to its $SOL PVP export feature and pledged to compensate affected users.
- Investigators are tracing transfers from MEXC withdrawals to a Kucoin deposit address, although neither exchange has been implicated in the theft.
Bitquery Traces $SOL Theft After Tradewiz Bot Activity Stops
Blockchain analytics firm Bitquery found that trading activity through the Tradewiz bot stopped 41 minutes into the main drain of funds. Despite the bot’s apparent halt, about 73% of the $SOL swept during that operation was taken afterward, creating a key timeline for investigators examining the incident.
Tradewiz’s September 30 security notice on X attributed the breach to private-key exposure involving its $SOL PVP export feature. The company instructed customers to stop using existing $SOL PVP wallet addresses and said, “We will fully compensate users for losses caused by this incident.”
A later Tradewiz update on X said the first refunds had been sent and that every claim required verification. Tradewiz also announced a precautionary pause in its EVM services while it carried out security checks. The company’s statements leave affected customers seeking answers on two separate issues: when their losses will be reimbursed and what failed in the systems intended to protect their wallets.
Tradewiz Wallet Security Assurance Faces Scrutiny
Tradewiz’s own wallet documentation has intensified questions surrounding the incident. Its FAQ allows users to import and export wallet keys but recommends against exporting them. The documentation states: “By not exporting your private keys, we can ensure 100% security of your assets.”
The subsequent disclosure has placed that assurance under scrutiny. Users will need an explanation of which wallets were exposed, how the $SOL PVP export feature was compromised and what security changes were made before services resumed.
So far, Tradewiz’s public statements have focused on security upgrades and compensation commitments without resolving those technical questions. A detailed account of the breach would help clarify the scope of the exposure and the measures intended to prevent a recurrence.
Investigators Follow Transfers to Exchange Accounts
On October 1, Tradewiz said on X that police were assisting with asset tracing and had contacted exchanges to seek identity and account-verification information. The company also said it would consider foregoing further legal action, where legally permitted, if those responsible cooperated and returned the assets.
Bitquery traced earlier funding to withdrawals from MEXC and later transfers toward a Kucoin deposit address. These connections do not implicate MEXC or Kucoin in the theft. They do, however, identify potentially relevant records that investigators may pursue as they work to establish who controlled the wallets and how the private keys were exposed.
For affected Tradewiz traders, the next significant developments will be the completion of reimbursements and the publication of a technical explanation of the breach. For investigators, earlier customer activity and exchange-related records may ultimately provide more useful evidence than the theft transactions themselves.
Why This Matters
The incident highlights the risks associated with private-key export features in crypto trading services. The blockchain trail can show how assets moved and identify possible investigative leads, but it does not by itself establish who controlled the wallets or how the keys became available. Tradewiz’s refunds, security review and cooperation with police and exchanges will therefore be central to determining the practical and legal outcome.
Frequently Asked Questions
What happened to Tradewiz’s $SOL wallets?
Tradewiz attributed the incident to private-key exposure involving its $SOL PVP export feature and told customers to stop using existing $SOL PVP wallet addresses.
Did Bitquery identify the person responsible?
No. Bitquery traced the movement of funds, including transfers connected to MEXC withdrawals and a Kucoin deposit address, but those connections do not establish who controlled the wallets or implicate either exchange in the theft.
Will affected Tradewiz users be reimbursed?
Tradewiz said, “We will fully compensate users for losses caused by this incident.” The company later said that initial refunds had been sent and that each claim required verification.

Leave a Reply