Victim-led investigation · Evidence dossier 01
The Sovryn Treasury Theft
This dossier concludes that Sovryn’s usable treasury and stakers’ promised fee revenue were stolen through an insider-directed course, while linked borrowing shifted losses onto RBTC lenders.
+ 12,215 ZUSDremoved from stakers’ claim accounting by the measured snapshot after Sovryn promoted BTC income
SOV holders locked capital after being promised Bitcoin income. RBTC lenders supplied Bitcoin to Sovryn’s lending pool. The record shows treasury reserves leaving, staker fee rights being taken, linked borrowers extracting RBTC, recovery being blocked, and the same financial network handling BOS sale proceeds. Real investors were left with the losses and continuing exposure.
Who was harmed
Four groups carried the economic consequences while leadership retained the information and authority needed to explain, stop, or reverse the disputed conduct.
- SOV stakers
- Promised BTC and stablecoin fee revenue was removed from claim accounting after users had bought, locked, or extended SOV positions.
- RBTC lenders
- Linked borrowers extracted Bitcoin against thin SOV collateral, leaving a modeled 4.0441-RBTC pool shortfall and later liquidations.
- Zero borrowers
- Redemptions forced borrowers to surrender Bitcoin collateral at timing chosen by the redeemer, taking away the BTC exposure they used Zero to preserve.
- Sovryn stakeholders
- Usable treasury assets—including 23.1464 RBTC worth about $2.12 million when transferred—left the Exchequer and remain unreconciled in a complete public ledger.
The case in seven steps
A coordinated wallet network concentrated control. Treasury assets then moved through repeated multisig approvals, staker fee rights were taken, and linked borrowers drew Bitcoin from the lending pool. Users warned leadership, recovery was blocked, and Sovryn assets later appeared in the same financial network used by BOS sale proceeds.
Terms used in this dossierOpen the wallet, asset, and governance glossary
- RBTC, WRBTC, and iWRBTC
- RBTC is Bitcoin represented on Rootstock. WRBTC is its contract-compatible form. iWRBTC is Sovryn’s RBTC lending-pool contract and receipt token.
- SOV stakers
- Users locked SOV for voting power and protocol-fee revenue. Longer locks can carry more voting weight.
- Address or wallet
- A blockchain account identified by a public address. The address shows transactions; a signing key controls what it can send.
- Exchequer multisig
- Sovryn’s shared treasury wallet. A multisig requires a minimum number of registered owners to approve a transaction; three approvals were required during the treasury transfers studied here.
- Bitocracy and SIP
- Bitocracy is Sovryn’s SOV-weighted proposal and voting system. A SIP is a Sovryn Improvement Proposal submitted to that system.
- FeeSharingCollector
- The contract that recorded and distributed protocol fees to SOV stakers. Its replaceable code and administrative controls are central to this case.
- ZUSD and USDt0
- Dollar-linked stablecoins used in the fee and incentive-program records.
- Governor and Guardian
- Sovryn’s Governor contracts process governance proposals. A Guardian shared wallet holds emergency administrative powers over them.
- B7 cluster
- A defined group of 70 addresses linked by first-funding paths to B7. Their repeated synchronized actions establish one centrally directed operation.
- Recurring wallet labels
- B7 is the common funding wallet; D9 is the Rootstock-to-Bitcoin transit wallet; 8C is the Tyrone-linked conversion, routing, and Safe-deployment wallet; DD names matching 2-of-5 destination and payment Safes on Ethereum and BNB Chain whose five-owner set is also used across the official BOS token-control network; and 0xfEE171…4a9e7e is the FeeSharing deployment and Exchequer-submission wallet named in Tyrone’s official deployment record.
- Exchange pool
- A reserve pool—also called an automated market maker, or AMM—that sets a token’s sale price. A large sale receives progressively less as it drains the available Bitcoin.
-
One coordinated setup became many wallets
A shared wallet requiring two of three owners funded common funding wallet
See the seed and wallet proofB7 · 0xb7d16f…ed81d8, which then paid the first transaction fees for scores of addresses. Ten previously unused core wallets sent their first outgoing transaction straight back to B7 within minutes. On a holder list they look separate; their two-way setup and later synchronized activity establish a centrally directed operation. -
The linked lending risk began years earlier
The B7-linked 2022 borrower wallet 8D51 opened a SOV-backed RBTC loan. It later received the same approximately 385,915 SOV that the February borrower wallet 4f39 sent, then put the full amount into three loans within 4m57s. The packet preserves the exact matching values. The surviving loan, identified as 0x839c…, now accounts for most of the cluster’s estimated shortfall.
Inspect the legacy loan -
BOS sale receipts entered a shared operations network
Origins recorded a $4.89 million USD-valued sale counter. Public-chain reconstruction now represents about $4.17 million at a matched daily-market benchmark, including high-confidence Bitcoin and Cardano collector pools. BOS receipts entered 0x509201, Sovryn’s Exchequer, and exchange routes later reused by Exchequer-derived funds.
Follow the cross-project fund paths -
Usable treasury assets were stolen into the same financial network
Twenty-seven material operations were used to steal RBTC and other reserves through a small set of routes. Every operation received the required approvals from at least three registered owners of the Exchequer multisig. Later tracing shows exact Bitcoin and Ethereum exchange infrastructure reused across BOS sale and Exchequer-derived routes.
Follow the treasury exits -
Stake moved, four loans opened, staker revenue was stolen
Seven B7-first-funded wallets withdrew approximately 10.05 million SOV from matured stakes in 1h52m24s. Four of them then opened loans inside 15m12s, supplying approximately 7.01 million SOV in the borrow calls for 1.465 RBTC in net payouts. Yago’s reward-pause announcement of the change documented here as theft followed the last opening by 12h35m, placing the loan session and policy change in one tightly ordered sequence.
See the synchronized sequence -
Users warned leadership; the positions stayed open
The transactions and lender risk were published. On Call #73, Yago said, “What’s it got to do with me?” He later called the loan link baseless and characterized the broader exchange as “conspiratorial thinking” and “noise.” The located public record contains no commitment to require repayment, pause affected lending, pursue any available protective action, or investigate the positions; linked voting defeated the executable recovery.
Hear the response and inspect the loans -
Value reconverged; lenders remained exposed
Borrower balances came back together, and cluster value reached USDt0 campaign signer
Follow the campaign-funding pathde169 · 0xde1690…5f6af2current registered owner-address of Sovryn’s 0x924f Exchequer multisig, which also guards both Governor contracts . That wallet later funded a USDt0 incentive campaign. August liquidations followed. At the 18 August measurement point, all five material cluster-linked positions remained active and below Sovryn’s required collateral level.
Search the evidence
Search by person, wallet, asset, proposal, or transaction. Every result returns to its original context and source record.
How findings are labeled and reproduced
We reconstructed transactions and contract balances directly from the named blockchains. Every current balance is tied to one stated block and time; this is a “pinned snapshot.” The public packet identifies any outside index used to find older or cross-chain records and provides the inputs needed to rerun each calculation.
- On-chain record
- A transaction or contract state stored on a blockchain.
- Direct source record
- A dated post, document, code artifact, image, or recorded statement attributable to its source.
- Dossier conclusion
- The finding drawn from the records identified beside it.
- Records authorities should compel
- Private evidence that should be preserved and obtained through lawful process.
“Dossier conclusion” identifies this publication’s evidence-based finding. The record supports a referral for suspected fraud, misappropriation, and related offenses. Courts and authorities determine charges and liability after compulsory process.
Reader-facing precision: token amounts and percentages are rounded to economically meaningful precision so the story remains legible. Search fields, linked explorers, source JSON, and the downloadable evidence packet preserve the exact underlying values.
0 matching records
0 sections · filed in dossier order
Select a record to inspect it in its original context.
No indexed evidence records match
Try a different person, address, proposal, asset, or transaction hash.
Try a known term:
Inspecting a matched record.
Four public notices that put leadership on notice
These disclosures establish what leadership was told and when. The underlying transactions, contract states, and calculations supply the technical proof below.
Disclosure #1
Public Disclosure #1 — Exchequer RBTC to exchange-style cluster (opens in a new tab)
First published the RBTC route and asked leadership to explain it.
Disclosure #2
Public Disclosure #2 — Founding-member SOV collateral loan (opens in a new tab)
Identified the four linked loans, warned of lender risk, and asked that they be closed.
Disclosure #3
Public Disclosure #3 — Exchequer total assets withdrawn (opens in a new tab)
Expanded the inquiry from RBTC to the usable treasury and challenged the FastBTC account.
Disclosure #4
Public Disclosure #4 — SOV loans liquidate, bad debt, and profit trail (opens in a new tab)
Recorded August liquidations, continuing impairment, and the subsequent borrower-cluster value trail.
Pinned records control every published figure. The dossier uses the block snapshots, transaction records, measurement definitions, and tracing methods in the downloadable public packet.
Part I · Control and treasury theft
How control was concentrated—and treasury assets left
The record shows advance control, repeated multisig execution, specific notice, blocked recovery, retrospective ratification, and measurable investor harm.
The evidence links pre-existing operational control to repeated treasury transfers, theft of staker fee rights, coordinated lending exposure, dismissal after specific notice, and governance action that preserved and later ratified the disputed change.
Control record
One funding root operated many apparent holders
Sovryn marketed direct Bitocracy control and user ownership while decisive powers remained with operational multisigs and a concentrated funding-and-voting network.
Statement
Public materials described a system directly controlled by Bitocracy and owned by its users, in which no single entity could make crucial changes.
Yago’s Bitocracy essay (opens in a new tab) · Sovryn fundraising statement (opens in a new tab)
Record
Exchequer retained both FeeSharing owner powers from October 2021. The live Guardian did not receive SIP-0047’s published seven-owner set. A strict B7-first-funded set supplied approximately 67.7% of source-attributed voting power.
Concentration snapshot: Rootstock block 9,162,625 · 18 Aug 2026 17:55:21 UTC. Reader-facing percentages are rounded; the packet preserves the exact fixed-point result.
How one funding root became many apparent holders
Splitting tokens and votes among addresses can create the appearance of diversification in a holder list. The audit tests whether those addresses were operated together: one source paying their first transaction fees, immediate return transactions, long dormancy broken in common sessions, exact-value handoffs, aligned votes, and synchronized staking and borrowing.
The seed
shared wallet requiring two of three owner approvals at funding B7 origin wallet · 0x777e7f…aaf97f sent 0.01 RBTC and then 5.89 RBTC to common first-funder and coordinated-cluster root B7 · 0xb7d16f…ed81d8 on 20 November 2020.
0.01-RBTC funding transaction (opens in a new tab) · 5.89-RBTC funding transaction (opens in a new tab)
- B7 origin-wallet approvals
- Two of three owners were required when it funded B7. The recovered approvals on both transfers were supplied by origin-wallet creator and co-signer
01ad · 0x01ad90…9dd990and origin-wallet co-signer and transaction submitterde25 · 0xde25ca…afc827. - B7 activity
- 134 indexed transactions, including 94 successful simple transfers to 69 recipients. The packet’s strict first-funder methodology attributes 70 addresses to the B7 root, including B7 itself.
- Two-way setup record
- Ten previously unused core wallets funded in the February 2021 batch made their first outgoing transaction straight back to B7 only 1m13s–6m20s later. Their transaction-fee settings fall into three repeated groups.
- What this establishes
- Ten newly activated wallets sent value back to B7 within 73–380 seconds as their first outgoing transaction, using the same transfer limit and three repeated transaction-fee groups. This establishes one coordinated setup session.
Transaction record
Common first funding; one uninterrupted funding batch; ten immediate return transactions; repeated transaction-fee settings; exact-value handoffs; multi-wallet staking bursts; synchronized February withdrawals and restakes; concentrated, aligned voting; and later borrower-value consolidation.
Coordination finding
The complete histories establish a centrally directed B7 operation. Low-frequency wallets repeatedly executed the same economic actions in narrow windows after long periods of inactivity.
Responsibility chain
Public records place Yago, Nahari, and Tyrone in the leadership, accounting, and implementation roles surrounding this coordinated operation. Authorities should obtain custody logs, devices, delegate instructions, and communications to allocate each key and instruction.
Inspect the ten first outgoing return transactions to B7
| Wallet | B7 funding | First outgoing transaction | Returned | Delay | Transaction-fee price |
|---|---|---|---|---|---|
February borrower; later RBTC hub b493 · 0xb493b1…a2c155 | B7 outgoing transaction #51 (opens in a new tab) 12:01:06 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 1m 40s | 18387381 |
February borrower 5011 · 0x50110e…f07962 | B7 outgoing transaction #53 (opens in a new tab) 12:05:31 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 3m 4s | 18387381 |
Large staker; transfer intermediary; recovery-opposition voter 78a0 · 0x78a0de…c0ffa7 | B7 outgoing transaction #54 (opens in a new tab) 12:12:54 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 1m 13s | 18387381 |
February borrower 91ab · 0x91ab7f…021684 | B7 outgoing transaction #55 (opens in a new tab) 12:16:46 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 2m 46s | 18387381 |
February borrower; former registered owner-address of the 0x924f Exchequer multisig; exact 2022 SOV handoff 4f39 · 0x4f3948…ae2e97 | B7 outgoing transaction #56 (opens in a new tab) 13:09:53 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 3m 29s | 8468389 |
Legacy 2022 borrower; large staker; recovery-opposition voter 8d51 · 0x8d5158…be0fb7 | B7 outgoing transaction #58 (opens in a new tab) 13:18:52 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 1m 32s | 8468389 |
Large staker; recovery-opposition voter; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e) a738 · 0xa7388d…3edce6 | B7 outgoing transaction #59 (opens in a new tab) 13:32:47 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 6m 20s | 1008468389 |
Large staker; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e) 9369 · 0x93698c…08a12e | B7 outgoing transaction #61 (opens in a new tab) 14:01:42 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0002 RBTC | 4m 21s | 8468389 |
Large staker; recovery-opposition voter 0d18 · 0x0d1831…238e91 | B7 outgoing transaction #62 (opens in a new tab) 14:18:43 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 1m 14s | 1008468389 |
Current registered owner-address of the 0x924f Exchequer/Governor-guardian multisig and Contracts Guardian shared wallet dfd4 · 0xdfd4da…1eba62 | B7 outgoing transaction #63 (opens in a new tab) 14:22:02 UTC | Recipient’s first outgoing transaction (opens in a new tab) simple wallet transfer · success | ≈0.0001 RBTC | 1m 29s | 1008468389 |
Why this is stronger than common funding: B7 paid the first transaction fees for ten recipients, and every recipient returned value to B7 within 73–380 seconds as its first outgoing transaction. Every return used the same simple-transfer limit, and the fee prices fall into three repeated groups. Together, those facts establish a coordinated setup session.
Inspect the complete-history activity profile
| Wallet and role | Outgoing transactions | Transaction-number range | Transactions other than votes | Active days other than voting | Longest outgoing gap (rounded) |
|---|---|---|---|---|---|
b493 February 2026 borrower | 53 | 0–52no missing outgoing nonces | 22 | 12 | 301 days |
5011 February 2026 borrower | 55 | 0–54no missing outgoing nonces | 26 | 9 | 297 days |
78a0 large staker · transfer intermediary | 36 | 0–35no missing outgoing nonces | 20 | 8 | 297 days |
91ab February 2026 borrower | 26 | 0–25no missing outgoing nonces | 21 | 10 | 512 days |
4f39 February 2026 borrower · former owner of the 0x924f Exchequer multisig (2021–2023) | 551 | 0–550no missing outgoing nonces | 527 | 176 | 298 days |
8d51 legacy borrower · large staker | 88 | 0–87no missing outgoing nonces | 57 | 25 | 282 days |
a738 large staker | 46 | 0–45no missing outgoing nonces | 16 | 11 | 297 days |
52e8 former owner of the 0x924f Exchequer multisig; every outgoing transaction confirmed one of its transactions | 49 | 0–48no missing outgoing nonces | 49 | 8 | 11 days |
9369 large staker | 40 | 0–39no missing outgoing nonces | 22 | 9 | 409 days |
0d18 large staker | 65 | 0–64no missing outgoing nonces | 24 | 13 | 297 days |
dfd4 current owner of the 0x924f Exchequer/Governor-guardian multisig and the 0xdd8e Contracts Guardian shared wallet · large staker | 52 | 0–51no missing outgoing nonces | 38 | 18 | 398 days |
How activity was counted: the table covers complete Blockscout histories of transactions started by each address. Contract-generated transfer records are not counted again as separate wallet transactions. The result shows low-frequency wallets repeatedly making the same economic moves together after long inactive periods.
Open the linked-wallet explorer directory
0xb7d16f650cb3b0754d61bdb3f6db79157ded81d8 Common first-funder and coordinated-cluster root0x91ab7f5df554566a8cdd2cfc722d0aa031021684 February borrower0x4f3948816785e30c3378ed3b9f2de034e3ae2e97 February borrower; former registered owner-address of the 0x924f Exchequer multisig; exact 2022 SOV handoff0xb493b1fb97f4cb2a1ea43a9ffed201e797a2c155 February borrower; later RBTC hub0x50110ef4e85a6a2e00a37d2eb30062000df07962 February borrower0x8d515805a21743c2f2f33aa12a420907cbbe0fb7 Legacy 2022 borrower; large staker; recovery-opposition voter0x78a0de7a48cce1a8759f353987731394d5c0ffa7 Large staker; transfer intermediary; recovery-opposition voter0xa7388d112406412f68c14e2924a070fd893edce6 Large staker; recovery-opposition voter; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e)0x52e8f03e7c9c1ef320ff7c31db78eaead18e5f85 Former registered owner-address of the 0x924f Exchequer multisig; every outgoing call confirmed one of its transactions0x93698c0150d17b98b820e9c2fdcfa161d508a12e Large staker; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e)0x0d1831ed7f1c5c55409a542d7e4bdda0c1238e91 Large staker; recovery-opposition voter0xdfd4da0e0e656af349e192b954baaef0fc1eba62 Current registered owner-address of the 0x924f Exchequer/Governor-guardian multisig and Contracts Guardian shared wallet0xa7a4a1afefdeadcb287769562fb65c3bbd83ccb6 Recovery-opposition voter; February restaker0xde1690480ef789beaa112157c7d123a5c85f6af2 Current registered owner-address of the 0x924f Exchequer/Governor-guardian multisig; FeeSharing approver; campaign signerThe complete 70-address attribution file publishes every full address, first-funding path, proof transaction, balance, and voting value. The complete-history coordination packet publishes the setup callbacks, address activity metrics, synchronized sessions, February linkage, methodology, and responsibility-record targets.
Common funding and coordination
Four February borrowers, the legacy borrower, large stakers, and a former Exchequer multisig owner were funded in one uninterrupted run of B7 transactions. In 2022, February borrower and former Exchequer multisig owner 4f39 · 0x4f3948…ae2e97 sent approximately 385,915 SOV to legacy 2022 borrower 8D51 · 0x8d5158…be0fb7 ; within 4m57s, 8D51 put the same underlying amount into three loans. The packet preserves the exact equality. Inspect the handoff (opens in a new tab) .
Guardian discrepancy
Zero of SIP-0047’s seven published Bitocracy Guardian signers was added to the live Guardian. In June 2026, Tyrone’s published role wallet sent and co-signed a valid owner rotation adding new owner wallets.
Allocate the coordinated operation
Authorities should obtain signer custody, delegate instructions, internal vote coordination, device/IP logs, and ownership records to assign each key and instruction within the established coordination pattern.
03 / Treasury theft
Treasury assets were stolen through repeated Exchequer multisig approvals
The Exchequer multisig was Sovryn’s shared treasury wallet. During this period, a transaction needed approvals from at least three registered owners. Twenty-seven material operations used that ordinary approval process and followed a small set of recurring routes over seven weeks.
Route explorers: Exchequer multisig 0x924f · 0x924f5a…2dc711 · Rootstock-to-Bitcoin transit wallet D9 · 0xd9ecb3…0a5d89 · conversion and bridge wallet 8C · 0x8c9143…84f50b supplied by the displayed Tyrone project account during the on-chain-matched May 2024 session · destination shared wallet on Ethereum DD · 0xdd2311…ee3fc4 · matching destination shared wallet on BNB Chain DD · 0xdd2311…ee3fc4 · FeeSharing deployment and Exchequer-submission wallet 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record
Value when the RBTC left the Exchequer: approximately $2.12 million. Using the closing BTC-USD price in the one-minute Coinbase Exchange candle containing each execution, 12 RBTC on 4 December 2025 was worth about $1,121,736; 6.7298 RBTC on 22 January 2026 about $605,630; and 4.4166 RBTC on 24 January 2026 about $395,314. Combined transfer-time estimate: $2,122,679.92. 4 December price (opens in a new tab) · 22 January price (opens in a new tab) · 24 January price (opens in a new tab) · method and arithmetic.
Treasury-linked DLLR redemptions forced Zero borrowers to surrender Bitcoin exposure
The investigation began with a narrower concern: treasury-linked DLLR was being turned into RBTC through Zero in a way that reduced Sovryn customers’ Bitcoin collateral exposure. At that point, the investigator did not yet know that the redemptions sat inside a much larger theft of usable treasury assets.
- 1Customers deposited BTC and borrowed a stablecoin.
A Zero customer locked RBTC in a Line of Credit and minted ZUSD against it. DLLR could be converted into its backing asset, ZUSD.
- 2Treasury-linked value took the protocol-redemption route.
Five Exchequer transactions sent approximately 569,214 DLLR to 8C. That wallet made matching DLLR-to-ZUSD calls and then eleven successful Zero
redeemCollateralcalls. First Exchequer DLLR exit (opens in a new tab) · last Exchequer DLLR exit (opens in a new tab) . - 3Zero allocated the redemption against borrowers.
Unlike an automated-market-maker sale, Zero’s redemption design (opens in a new tab) cancels the redeemer’s ZUSD and removes the oracle-priced RBTC equivalent from active Lines of Credit, beginning with the lowest-collateralized eligible positions. First successful Zero call (opens in a new tab) · last successful Zero call (opens in a new tab) .
Why that harmed Sovryn customers
Zero forced the timing of the collateral reduction. Each redemption reduced both debt and BTC collateral at the redeemer’s chosen moment, taking from borrowers the Bitcoin exposure they had used Zero to preserve.
The route also contracted ZUSD/DLLR supply instead of helping it grow. The dossier concludes that using treasury-controlled assets this way prioritized treasury conversion over minimizing harm to the protocol’s own users.
Attribution supported by the transaction record
The curated sequence records five treasury DLLR exits, five aggregator calls, eleven successful Zero redemptions, and approximately 6.2281 RBTC returned after the batches. The successful redemption inputs exceed the identified treasury DLLR because 8C held commingled balances. The attributable finding is a treasury-linked sequence; commingling prevents allocation of every redeemed ZUSD unit or returned satoshi solely to Exchequer DLLR.
Inspect the full transaction sequence and attribution limit.
Yago’s explanation
Yago later described the activity as an “overall consolidation that we did of the treasury.”
The question specifically raised the December–January DLLR conversions. Yago said Sovryn wanted to hold most treasury funds in BTC because “the project does the same.” Community Call #72, beginning at 43:52 and continuing at 46:40.
What the public wallet record showed
By the time of the call, the Exchequer multisig held only 0.7134 RBTC. The record traces approximately 23.1464 RBTC—worth approximately $2.12 million when the three transfers left the Exchequer—through the Rootstock-to-Bitcoin transit wallet (D9) to one exchange account address; about $522,242 in reconciled stablecoin receipts, 12.12 ETH, and 52.85 BNB reached the cross-chain destination shared wallets (DD). No public ledger has reconciled those off-wallet holdings back to Sovryn.
The description of consolidating the treasury into BTC does not match the visible destinations and asset mix. All 27 operations used valid Exchequer multisig approvals. FeeSharing deployment wallet and Exchequer signer; 27 approvals 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record approved all 27. Three other registered Exchequer owner-addresses— Exchequer owner-address; 21 approvals 0x9e9c0a…5dcf22 · 0x9e9c0a…5dcf22 , Exchequer owner-address; 20 approvals 0xa0fdcd…30ed8b · 0xa0fdcd…30ed8b , and Exchequer owner-address; 13 approvals 0xeabb83…152a86 · 0xeabb83…152a86 —completed the active signer group.
Complete question and answer describing overall treasury consolidation
Watch the full Community Call #72 on YouTube (opens in a new tab) · source recording and captions checked
Inspect the underlying DD and BOS custody record
Cross-project custody record
The DD treasury destination shares its control network with BitcoinOS
DD received assets routed from Sovryn’s Exchequer. Matching DD Safes on Ethereum and BNB Chain were configured with the same five owner addresses as the Safe that owns the official BOS token and the Safes holding BitcoinOS’s published allocation buckets. The record establishes shared custody, signer, deployment, and payment infrastructure across Sovryn treasury activity and BitcoinOS token administration.
- Separation asserted; a contribution path contemplated
Yago wrote, “Sovryn has not been funding BitcoinOS” (opens in a new tab) , described separate contributors and funding, and later said “Sovryns treasury is not being requested for anything.” (opens in a new tab) He repeated the distinction on Community Call 63 (opens in a new tab) . On 2 July he added that, for Sovryn to receive 10%, it would need to “invest between $5m-$100m in value or provide in-kind value to that degree” (opens in a new tab) and actively help raise BOS funds.
- Official contributions acknowledged
SIP-0083 (opens in a new tab) said Sovryn had made substantial contributions throughout BitcoinOS development and committed Sovryn resources to technical development, audits, interfaces, marketing, infrastructure, and network operations. Yago then called Sovryn a significant BitcoinOS participant (opens in a new tab) .
- Cross-payments admitted; mingling denied
Yago said funds had been “paid out by BOS on behalf of Sovryn” (opens in a new tab) and needed year-end consolidation. Minutes later, asked whether Sovryn was mingling funds with BOS, he answered “No.” (opens in a new tab) The shared-key and payment record below requires a transaction-level reconciliation of those statements.
Asset route
- Sovryn Exchequertreasury-derived assets
- 8C and bridge routesconversion and deployment layer
- DD on two chains2-of-5 destination and payment Safes
Owner-address linkage across time
- B7Rootstock · Dec 2020 · 0.1 RBTC
- 0x509201…AbD6cross-chain operations address
- 0x5C07…96C2Ethereum first funding · Oct 2025 · 0.05 ETH
Control overlap
- 8C deployerDD and BOS Safe families
- Same five owner addressesrepeated 2-of-5 control set
- BOS administrationtoken owner and allocation Safes
01 · One control set
DD and the BOS Safe family use the same five owner addresses
8C created Ethereum DD (opens in a new tab) 63 seconds after creating its matching BNB Chain Safe (opens in a new tab) , using identical setup data, the same five owners, and a 2-of-5 threshold. The same 8C wallet created the Safe that owns the official Ethereum BOS token (opens in a new tab) and the allocation Safes with that exact owner set.
The initial BOS balances reconcile the official schedule: 6.72 billion BOS, exactly 32%, reached the inferred ecosystem Safe; three inferred founding-entity Safes received 7.35 billion BOS, exactly 35%, after accounting for their 100-BOS tests and 50-BOS returns. Official allocation schedule (opens in a new tab) · allocation execution (opens in a new tab) .
02 · Long-running operational continuity
0x509201…AbD6 links B7, Sovryn’s bridge, payments, DD, and BOS
B7 sent 0.1 RBTC to 0x509201…AbD6 in December 2020 (opens in a new tab) . The same address later sent at least 8.55 million USDT across 18 transfers to the official Sovryn Ethereum bridge (opens in a new tab) , solely controlled an earlier recurring-payment Safe, approved every observed Ethereum DD execution, and is listed throughout the BOS Safe family.
Five external recipients from that earlier CSV-style recurring-payment record (opens in a new tab) reappeared together in DD’s December 2025 batch. That functional continuity is stronger than a shared-wallet-format resemblance: it connects the operator key and recipient network across years.
The later BOS sale-wallet reconstruction adds direct proceeds links: the post-maintenance Ethereum collector transferred 204,103.50752 USDT, 30,056.588245 USDC, and 3.605528 ETH to 0x509201, while its Rootstock instance sent swept participant RBTC into Sovryn’s Exchequer.
03 · Concentrated execution
The same pair approved all 14 Ethereum DD executions
0x509201…AbD6 and 0xcD9003…fBAA supplied every observed Ethereum DD quorum. DD then sent 70 ETH on 1 December 2025 (opens in a new tab) and 120,000 USDT on 30 March 2026 (opens in a new tab) directly to 0x509201…AbD6; the recipient approved both payments and 0xcD9003…fBAA supplied the second signature.
On BNB Chain, DD’s executed transaction used 0x509201…AbD6 with 0x5C07…96C2 . The five addresses are Safe owner addresses, not five identified independent people.
Inspect the five owner addresses and their demonstrated roles
| Owner key | Evidence-based role | Demonstrated basis | Human controller |
|---|---|---|---|
0x5092019A3E0334586273A21a701F1BD859ECAbD6 | Long-running Sovryn and BitcoinOS treasury-linked operational owner address; recurrent DD signer and DD payee Confidence: very high | Received RBTC from B7; sent 18 USDT transfers totaling 8,550,668.522386 USDT to Sovryn's official Ethereum bridge; solely controlled the earlier recurring-payment Safe; provisioned three later shared owner addresses; approved every Ethereum DD execution; received 70 ETH and 120,000 USDT from DD; and is listed throughout the BOS Safe family. | unidentified |
0xcD90036b1b1E2576E380Fa407Cb8021f4f4efBAA | Principal BitcoinOS/DD owner address and recurrent DD co-signer Confidence: very high | Supplied the second approval on every observed Ethereum DD execution and is listed throughout the related BOS and DD Safes. | unidentified |
0x5C07E4CC17e3d6076fc7963235B1e3299b1596C2 | Shared DD/BOS owner address and BNB DD co-signer directly provisioned by 0x509201…AbD6 Confidence: high | Co-approved the observed BNB Chain DD execution and is listed throughout the DD/BOS Safe family. The address has no located Rootstock activity; its B7 relationship is the proved two-hop path through 0x509201…AbD6. | unidentified |
0xe31cfdF3C6E4FE91f8873227e025725bb9dF67C6 | Lightly used shared DD/BOS owner address provisioned by 0x509201…AbD6 Confidence: high | 0x509201…AbD6 supplied its first Ethereum funding; the address is listed throughout the exact five-owner DD/BOS Safe family. | unidentified |
0x59c4d24687f5eE6C846Df010a49b55281d2Ded0f | Lightly used shared DD/BOS owner address provisioned by 0x509201…AbD6 Confidence: high | 0x509201…AbD6 supplied its first Ethereum funding; the address is listed throughout the exact five-owner DD/BOS Safe family. | unidentified |
What leadership said when the customer harm was asked directly
On Community Call #73, Yago was asked why the treasury route redeemed against users rather than using another conversion path. He said he was not involved in that choice. Nahari said he could not recall the exact reason and suggested it might have concerned BabelFish liquidity.
Later in the same call, continued questions were characterized as baseless, conspiratorial, noise, bad faith, and a failure to understand—without a transaction-level ledger that reconciled the challenged routes.
Why the later record changes the meaning of those answers
The initial complaint concerned a specific customer-protection problem. Only later did the wallet record reveal the larger treasury theft and multiple destination routes. The explanations then expanded from ordinary consolidation into BTC, to exchange payments and a general FastBTC-liquidity account, while the reason for choosing Zero redemptions against users remained unreconciled.
This victim-led dossier concludes that the repeated omission of material context, shifting explanations, and dismissal of evidence amounted to deception and gaslighting. Investors experienced each new discovery as another reason to doubt assurances they had already been given. The public record proves the statements and the unreconciled sequence; private communications and account records remain necessary to determine each person’s intent and instruction.
Complete question and answer containing the inability to explain the precise redemption method
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
Complete question and answer containing the bad-faith, lack-of-understanding, and no-deep-mystery response
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
Two distinct RBTC flows: November FastBTC and the later 23.1464-RBTC route
The stolen RBTC reached one exchange deposit address
bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5 (opens in a new tab)
Nahari confirmed the destination type
“It is an exchange wallet. It has nothing to do with OKX.”
That Community Call #73 statement turns “exchange destination” from a third-party label inference into a direct management acknowledgment. Nahari then described centralized exchanges as being used to swap assets for payments and supplied the broader FastBTC-liquidity account.
What that admission supports
Nahari’s specific knowledge establishes that leadership recognized the exchange destination and asserted a business purpose for it. Exchange KYC and account records can identify the credited customer, beneficial owner, trades, withdrawals, and fiat proceeds.
OKLink labels the terminal address Gemini (opens in a new tab) . A directly connected consolidator carries an OKEx label on BitInfoCharts (opens in a new tab) . Together with Nahari’s explicit denial of OKX, Gemini is the leading public venue inference, not a settled identification. Exchange account and customer-identification records are required to resolve it.
| Route | Terminal receipt (UTC) | BTC | Bitcoin transaction |
|---|---|---|---|
| November FastBTC route 1 | ≈4.13 | 0d7c9836b5…9098e8 | |
| November FastBTC route 2 | ≈7 | 8ee46e3c42…2f6703 | |
| December Exchequer route | ≈11.999 | 45f6e40a5c…d2b173 | |
| 22 January Exchequer route | ≈6.7205 | f753d78eba…fba93e | |
| 24 January Exchequer route | ≈4.42 | dd5b45fe83…6efdc4 |
Convergence proved; customer identity unresolved. The two November receipts total approximately 11.1299 BTC. The three later receipts total approximately 23.1395 BTC. All five terminate at the address above; only the exchange can identify the credited account, controller, and beneficial owner.
Statement
On Call #73, Nahari confirmed the destination was an exchange wallet, denied it was OKX, and supplied a general third-party FastBTC-liquidity explanation for exchange-bound movements. He referred to roughly 80–100 BTC across the systems.
Record
November FastBTC sources sent approximately 11.1212 RBTC into the Rootstock-to-Bitcoin transit wallet (D9). The later Exchequer route sent a separate approximately 23.1464 RBTC—worth approximately $2.12 million at the transfer times—in December and January. A payment or liability of that scale should be supported by a named counterparty, agreement, invoice, authorization, liability ledger, and transaction mapping. The public explanation supplied none of them.
Records authorities should compel Obtain the complete FastBTC accounting packet and both Rootstock- and Bitcoin-side liability records.
Complete question and answer containing the general third-party FastBTC explanation
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
Exchequer transaction ledger · 27 operations
| UTC / block | Asset / amount | Route | ID | Approvers | Execution |
|---|---|---|---|---|---|
#8,275,774 | ≈12 RBTC | D9 / PowPeg route Rootstock-to-Bitcoin transit wallet D9 0xd9ecb3…0a5d89 · 0xd9ecb3…0a5d89 | 2099 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xf09e5dde…a7d1d6 |
#8,276,441 | ≈200,000 XUSD | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2101 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x07052fa1…f4973c |
#8,277,370 | ≈202,460 XUSD | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2102 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0x78deb5f3…f57506 |
#8,277,710 | ≈200,000 MOC | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2103 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xeabb83…152a86 | 0x032087d6…29142e |
#8,279,785 | ≈363,500.89 MOC | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2104 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x495f862c…65ffd5 |
#8,290,267 | ≈0.14 ETHes | ETH bridge to DD (0.1302 ETH after fee) destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2106 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0xc6f569df…acddac |
#8,291,602 | ≈12 ETHes | ETH bridge to DD (11.99 ETH after fee) destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2114 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0xcaa7c69e…ad6c9a |
#8,298,386 | ≈100,000 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2123 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0x2c78a6ef…13b41e |
#8,299,259 | ≈2.09 BNBbs | BNB bridge terminal receipt 2.085 BNB destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2131 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0x42dcbd61…231e9a |
#8,299,262 | ≈0.78 BNBs | BNB bridge terminal receipt 0.772639178690725711 BNB destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2132 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0xbbc42bfc…f7cb65 |
#8,301,076 | ≈100,000 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2135 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x298ea984…7bf16b |
#8,301,277 | ≈50 BNBbs | BNB bridge terminal receipt 49.996 BNB destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2137 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xd47074af…44e3fb |
#8,321,340 | ≈100,000 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2138 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x061e0602…aefc2b |
#8,324,949 | ≈794,380 SOV | FeeSharing deployment wallet and Exchequer owner-address0xfee171…4a9e7e | 2139 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0xeabb83…152a86 | 0x3c72607f…84282d |
#8,326,566 | ≈46.01 ETHes | ETH bridge request; far-side receipt not located destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4 | 2141 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0x4a4af853…7a2b02 |
#8,326,568 | ≈100,000 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2142 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 | 0xa0b1bd1f…f65e61 |
#8,342,107 | ≈169,214 DLLR | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2144 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b | 0x5661bbfa…0797fa |
#8,342,801 | ≈687,320 SOV | Exchequer owner-address 0x9e9c0a…5dcf220x9e9c0a…5dcf22 | 2145 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0x12dc23cb…adda6d |
#8,351,352 | ≈11,710 USDCes | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2151 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xab016cdb…8000ff |
#8,351,352 | ≈1,650 USDCbs | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2152 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0x87f9c88d…46b8ff |
#8,351,353 | ≈13,260 USDTes | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2153 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xeff95ec1…548ae5 |
#8,351,358 | ≈5,400 USDTbs | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2154 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0xbf0f08ec…e446e9 |
#8,440,529 | ≈100,000 rUSDT | 8C bridge/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2156 | 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 | 0x8d135d4b…d433a9 |
#8,447,816 | ≈6.7298 RBTC | D9 / PowPeg route Rootstock-to-Bitcoin transit wallet D9 0xd9ecb3…0a5d89 · 0xd9ecb3…0a5d89 | 2157 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0xc9f566be…a96127 |
#8,448,302 | ≈3.65 BPRO | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2162 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0xea3646c2…4809a3 |
#8,448,306 | ≈55,000 DOC | 8C converter/custody conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b | 2163 | 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b | 0x7c176380…080a12 |
#8,454,487 | ≈4.4166 RBTC | D9 / PowPeg route Rootstock-to-Bitcoin transit wallet D9 0xd9ecb3…0a5d89 · 0xd9ecb3…0a5d89 | 2164 | 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xeabb83…152a86 | 0x336a6d72…6bdd5f |
Gross on-chain asset estimate for 1 December. A realized-output valuation puts the material non-SOV assets at $2.66 million. Valuing the approximately 5.07 million SOV balance with Sovryn’s on-chain reference price adds about $536,947, for a reproducible gross estimate of about $3.20 million. A separate same-time price check reached $3.25 million. These are asset values before unidentified liabilities or off-chain accounts. BTC price (opens in a new tab) · ETH price (opens in a new tab) · BNB price (opens in a new tab) · balances, realized outputs, and valuation method.
By 18 August, the Exchequer multisig held 0.7134 RBTC and approximately 3.44 million SOV; selling that entire SOV balance through the only identified exchange pool quoted approximately 0.5029 WRBTC. The theft had left Sovryn with effectively no usable, diversified on-chain liquidity. The public packet keeps every input and values SOV separately so its thin market is not treated like cash.
Records needed to complete the treasury accounting
- Exchequer minutes, internal votes, budgets, and signer instructions
- Centralized-exchange customer-identification, subaccount, deposit, trade, and withdrawal records for the Bitcoin cluster
- Signer identities and custody records for 8C and all five shared DD/BOS owner addresses, plus DD payee schedules, Safe execution records, and beneficial-controller mapping
- Sovryn and BTC OS Limited general ledgers, intercompany accounts, journal entries, cost allocations, reimbursements, invoices, payroll, processor contracts, and bank/exchange statements
- FastBTC agreements, provider identities, beginning/ending liabilities, and payment reconciliation
- Destination-side proceeds tracing, BOS allocation and vesting records, and every related-party or BOS-on-behalf-of-Sovryn payment record
Part II · Investor harm
Sovryn promoted Bitcoin income—then took the fees
Sovryn promoted staking as a way to earn Bitcoin and stablecoin revenue. Sixteen days after its January solicitation, a Tyrone-linked deployment workflow shut live fee claims. In February, the Exchequer multisig replaced the contract code and stole stakers’ rights to all newly recorded RBTC and ZUSD fees before any Bitocracy vote.
2955fb83…457755e4.Why this is evidence of deceptive solicitation and investor damage
The advertisement used a present-tense instruction to enter the staking proposition: lock SOV now and receive Bitcoin and dollar-denominated revenue. Sovryn’s product page (opens in a new tab) , earn page (opens in a new tab) , and staking article (opens in a new tab) repeated the same economic promise.
Sovryn publicly identified Yago as project lead. He designed and joined the small Exchequer framework, announced the revenue redirection documented here as theft, repeatedly described what “we” decided, defended executive action before a vote, and sponsored its later ratification. The official advertisement and the later theft therefore belong to the same leadership and policy record.
Yago personally promoted the same investment logic. In December 2024 he wrote that SOV paid yield from protocol revenue “primarily in the form of BTC” and that making returns more obvious would increase staking desirability. At 13:58 UTC on 17 February 2026—twelve minutes before the pause announcement—he wrote that staking should remain “compelling long-term” and that staker distributions should come from “real revenue.” Read the 2024 statement (opens in a new tab) · read the 17 February statement (opens in a new tab) .
- Solicitation: Sovryn told readers to stake immediately for up to 21.37% APR in BTC and USD.
- Undisclosed live intervention: FeeSharing deployment and Exchequer-submission wallet
0xfee171…4a9e7e · 0xfee171…4a9e7enamed as sender in Tyrone Johnson’s official deployment record deployed code that disabled fee claims; enough owners of the Exchequer multisig0x924f · 0x924f5a…2dc711activated it that day. - Leadership announcement: Yago announced the pause and the revenue redirection documented here as theft after the operational path had already been used on mainnet.
- Staking-revenue theft executed: the Exchequer multisig activated the replacement code. The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e then added RBTC and ZUSD to the 100%-withholding list by 11:44:51. Tyrone’s official deployment record names this wallet as its sender. The vote came later.
The same promise remained live after the staking-revenue theft
Captured on 20 August 2026—nearly six months after the Exchequer multisig activated 100% withholding—the official staking page still said “up to 20% APR,” “rewards you in BTC,” and “PAYOUTS IN BTC,” beside a “BUY SOV” action. The archived HTML begins with Webflow metadata reading “Last Published: 9 February 2026,” after the January claim shutdown and before Yago’s 17 February notice.
3e9cba85…25a33a0.
40740fde…37d8c6.Current mismatch: the official page continued soliciting staking with BTC-return language while the active contract routed listed RBTC and ZUSD fees away from staker claim accounting. This continued publication is direct evidence for the deception, materiality, reliance, and damages inquiry.
Representation and inducement
The official account told readers to “Stake SOV right now” for BTC and USD returns. Yago had already described BTC revenue as the basis of SOV yield and as something that made staking desirable.
Capital committed while the message was live
Between the 12 January promotion and Yago’s 17 February notice, 15 beneficiary wallets directly staked approximately 111,068 SOV. 20 wallets extended locks covering approximately 9,962,956 SOV. The extension total measures already-locked positions, not new purchases.
Knowledge, control, and omission
The Exchequer multisig used its retained power to stop claims on live mainnet on 28 January. Yago later said “we” had decided on the revenue redirection documented here as theft and defended executive action before a vote. The promotion and official staking pages did not explain this retained control, and the staking page continued advertising BTC payouts after 100% withholding went live.
Loss and investor files
The replacement code stole stakers’ rights to approximately 0.2912 RBTC and 12,215 ZUSD by excluding those fees from claim accounting as of the 18 August snapshot. Each victim file should connect the dated representation to purchases, staking or lock extensions, fees received, remaining holdings, and realized or continuing loss.
What the contract record shows: measured at Rootstock block 9,162,805 on 18 August 2026, both administrative-owner checks still pointed to the Exchequer multisig 0x924f · 0x924f5a…2dc711 . The totals from 90 RBTC and 46 ZUSD fee events exactly matched the contract’s internal accounting records; no withdrawal event was recorded.
Yago’s public explanation
“The answer is very simple. It’s because it happened. So we don’t know in advance what is going to happen… Now that it has happened, we’re taking action again.”
Community Call #72, answering why the Bitcoin decline caused the response.
The earlier action and price record
The live claim shutdown was deployed on 28 January at 15:29 UTC and activated at 17:51 UTC. Coinbase candles place BTC near $89,139 at deployment and $90,350 at activation. The larger daily decline followed: the 28 January close was about $89,162; the 29 January close was about $84,513, down 5.2%. Inspect the daily candles (opens in a new tab) .
The 29 January fall could not have first triggered the 28 January action. The same retained administrative route had already been prepared and used to stop claims on live mainnet. Yago later cited the recent BTC decline when justifying the February change that stole staker fee rights. Inspect the Coinbase interval (opens in a new tab) · inspect Tyrone’s January code record (opens in a new tab) .
Complete question and answer on the treasury reaction, BTC exposure, and replenishment
Watch the full Community Call #72 on YouTube (opens in a new tab) · source recording and captions checked
Yago’s later position
Yago later said FeeSharingCollector had never been—and was never intended to be—controlled by Bitocracy. Read Yago’s FeeSharing response · 8 March 2026 (opens in a new tab) .
Earlier governance expectation and actual power
SIP-0046 stated that FeeSharingProxy was an exception to Exchequer ownership (opens in a new tab) . Chain history shows both administrative roles for the live FeeSharing contract transferred to the Exchequer multisig in October 2021 and remained there through the February theft.
Code and deployment
Tyrone Johnson authored the January shutdown and February withholding code. His official deployment commit records FeeSharing deployment and Exchequer-submission wallet 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record as sender. That wallet submitted the Exchequer multisig code replacement 51 seconds later and the RBTC/ZUSD operations during the next 2m25s. Inspect the official deployment record (opens in a new tab) .
Execution
Enough owners of the Exchequer multisig approved the replacement code. It went live on 25 February; RBTC and ZUSD were placed on the 100%-withholding list. No prior Bitocracy proposal was located.
Measured staking revenue stolen from staker claim accounting
The code excluded approximately 0.2912 RBTC and 12,215 ZUSD from the accounting entries that let stakers claim fees. Those amounts remained under an Exchequer-controlled withdrawal function.
How this record supports a fraud referral and investor damages
The official solicitation, undisclosed retained control, pre-announcement mainnet intervention, Yago’s announcement, defense, and ratification sponsorship, continuing post-theft marketing, and measurable theft of fee rights form a documented deceptive-inducement record. Each investor’s loss schedule should connect the public evidence above to:
- SOV purchase transactions, dates, quantities, and prices
- Staking transactions, lock duration, expected fees, and actual fees received
- The advertisement or revenue statement the investor saw and when they relied on it
- Unstaking or sale transactions, current holdings, and the method used to value the loss
- Messages, call recordings, or forum posts showing what leadership knew and when
- Internal campaign approval, FeeSharing planning, Exchequer multisig instructions, and analytics showing who targeted or viewed the promotion
Submit purchase, staking, reliance, and loss records through the encrypted evidence intake.
FeeSharing transaction ledger · 15 entries
| UTC / block | What happened | Transaction |
|---|---|---|
#3,769,580 | The contract was created with the deployer holding both administrative roles | 0x92560ba4…245e5e (opens in a new tab) |
#3,769,600 | First owner role transferred to Exchequer | 0xdb6f399d…dc1d26 (opens in a new tab) |
#3,769,602 | Second owner role transferred to Exchequer | 0xd095df4d…4c3312 (opens in a new tab) |
#8,469,257 | The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e deployed code that disabled staker fee claims | 0x6fa7f9ca…f306a7 (opens in a new tab) |
#8,469,265 | The 0xfEE171…4a9e7e deployment wallet submitted the claim-shutdown request as Exchequer multisig transaction 2166 | 0x0fd70e59…22be1a (opens in a new tab) |
#8,469,615 | Enough Exchequer multisig owners approved and activated the claim shutdown | 0xedc2cf4b…d93e96 (opens in a new tab) |
#8,475,868 | The 0xfEE171…4a9e7e deployment wallet submitted Exchequer multisig transaction 2167 to restore the earlier code | 0xec720d14…d1d071 (opens in a new tab) |
#8,475,916 | Enough Exchequer multisig owners approved and restored claims after 44h20m01s | 0x1ba84692…52a33b (opens in a new tab) |
#8,544,919 | The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e deployed the 100%-withholding code | 0x6b281895…696e96 (opens in a new tab) |
#8,544,922 | The 0xfEE171…4a9e7e deployment wallet submitted the code replacement as Exchequer multisig transaction 2196 | 0x9c78c855…9a947b (opens in a new tab) |
#8,544,924 | The 0xfEE171…4a9e7e deployment wallet submitted 100% RBTC withholding as Exchequer multisig transaction 2197 | 0x4d9d1306…162601 (opens in a new tab) |
#8,544,926 | The 0xfEE171…4a9e7e deployment wallet submitted 100% ZUSD withholding as Exchequer multisig transaction 2198 | 0x01c6a7b8…a7c431 (opens in a new tab) |
#8,565,302 | Enough Exchequer multisig owners approved and activated the replacement code | 0x1c8293f9…481c60 (opens in a new tab) |
#8,565,356 | The 0xfEE171…4a9e7e deployment wallet executed the RBTC 100%-withholding addition | 0x994d2cac…04d8ba (opens in a new tab) |
#8,565,358 | The 0xfEE171…4a9e7e deployment wallet executed the ZUSD 100%-withholding addition | 0x33b47515…fe1138 (opens in a new tab) |
Loans and lender harm
Linked wallets borrowed Bitcoin against illiquid SOV
The February loan session joined synchronized stake withdrawals, four B7-linked openings, and coordinated restaking. It was not the cluster’s first lender exposure: a legacy position opened in 2022 now accounts for most of the estimated shortfall. The located record contains no closure, pause, repayment demand, committed cure, or independent risk action before liquidation. The calculations assume no borrower repayment, new capital, insurance, or outside rescue.
Four-loan outcome snapshot: Rootstock block 9,158,536 · 17 Aug 2026 07:23:15 UTC. The separate all-eleven model for the iWRBTC lending pool is pinned to block 9,162,594.
The coordinated February loan sequence
Seven B7-first-funded wallets withdrew more than 10 million SOV; four opened SOV-backed loans, and Yago’s staking-revenue announcement followed the final opening by 12h35m18s.
- Seven linked wallets withdrew approximately 10,048,901 SOVFour acted inside 7m13s. Three more followed 1h38m later; the first three transactions in the opening group used the same gas price and gas limit.
- Four of those wallets opened loans inside 15m12sEach borrower had withdrawn matured stake 186–7,083 seconds earlier. The borrow calls supplied approximately 7,006,709 SOV, and the borrowers received 1.465 RBTC net.
- Yago announced the staking-revenue change The reward pause and the change documented here as theft (opens in a new tab) followed the fourth loan opening by 12h35m18s.
- Linked wallets rebuilt long-duration stakes togetherThree non-borrowers restaked the exact amounts they had withdrawn. With three other linked wallets, approximately 6,986,587 SOV entered stakes inside 43m16s; five used the same 16 February 2029 lock target.
Dossier conclusion The withdrawals, loan openings, reward announcement, exact-value restakes, shared lock targets, and repeated prior sessions establish a coordinated sequence supporting investigation of advance knowledge and conflicts. Custody, instruction, and internal planning records can allocate the people directing it.
8 March 2026
Public notice
Warning and evidence delivered
Public Disclosure #2 (opens in a new tab) listed the four borrow transactions, tied their timing to the reward announcement, warned that illiquid collateral endangered RBTC lenders, asked Yago and Nahari to close the loans immediately, and requested stronger collateral rules.
- Power to act
- Leadership could call for repayment, initiate an independent risk investigation, support a pause or rule change, disclose control and conflicts, or back the requested governance remedy.
- Recorded response
- On Call #73 Yago disclaimed relevance and said SOV owners could do what they chose.
- Omitted
- No commitment to close the loans, require repayment, pause exposure, investigate coordination, or protect existing RBTC lenders.
- Protective action not taken
- The four loans remained open; no later collateral deposit occurred.
- Later on-chain outcome
- Nine August liquidations seized approximately 1.57M SOV; all four positions remained active and unsafe with approximately 1.1151 WRBTC outstanding.
- Why the dossier infers intent
- Specific notice, ability to mitigate, dismissal, continued inaction, and the later predicted harm support an inference of knowing disregard.
- Records to compel
- Borrower-key custody, internal notice, risk review, repayment instructions, and all communications from 17 February through the August liquidations.
- Later confirmation
- Disclosure #4 (opens in a new tab) documented liquidation and the continuing pool impairment.
Yago responds when the founding-member loan is raised
Excerpt checked against the full call
“No, of course not. What’s it got to do with me? Or the conversation that we’re having? Like, people who own SOV can do with it whatever they choose.”
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
57:40–58:40 follow-up
The question explicitly stated Sovryn’s responsibility to protect RBTC lenders from losses caused by illiquid collateral.
What the answer did
Yago shifted the remedy toward future collateral-rule changes. He supplied no commitment to close the identified loans, require repayment, pause the risk, disclose conflicts, or begin an independent investigation.
Follow-up states the duty to protect RBTC lenders from illiquid collateral
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
Loan transaction ledger · 4 openings and 9 liquidations
| UTC / block | Borrower / loan | Principal | Collateral | Transaction |
|---|---|---|---|---|
#8536319 | 0x91ab7f…021684 0xeb0bb06d…949ebf | ≈0.3862 WRBTC | ≈1,839,490 SOV | 0xb55fb894…fcc815 (opens in a new tab) |
#8536335 | 0x4f3948…ae2e97 0x39519639…6553b0 | ≈0.4614 WRBTC | ≈2,198,044 SOV | 0x1082b3e0…7b865d (opens in a new tab) |
#8536347 | 0xb493b1…a2c155 0xa499ced3…f8d45a | ≈0.317 WRBTC | ≈1,510,060 SOV | 0x6b7ddf65…8a8489 (opens in a new tab) |
#8536354 | 0x50110e…f07962 0xbecb523d…83b474 | ≈0.305 WRBTC | ≈1,452,809 SOV | 0xc0c07f1a…c86074 (opens in a new tab) |
| UTC / block | Loan | WRBTC repaid | SOV seized | Transaction |
|---|---|---|---|---|
#9155133 | 0xa499ced3…f8d45a | ≈0.1065 | ≈454,473 | 0x34fb3757…937f3a (opens in a new tab) |
#9155138 | 0xbecb523d…83b474 | ≈0.012 | ≈51,401 | 0x0a09be12…bbb233 (opens in a new tab) |
#9155151 | 0x39519639…6553b0 | ≈0.009 | ≈38,491 | 0x00b1c903…942ac6 (opens in a new tab) |
#9155159 | 0x39519639…6553b0 | ≈0.127 | ≈544,045 | 0x79183dc6…54159f (opens in a new tab) |
#9155187 | 0x39519639…6553b0 | ≈0.05 | ≈239,260 | 0x2036ecac…caae8a (opens in a new tab) |
#9155488 | 0xa499ced3…f8d45a | ≈0.02 | ≈97,573 | 0xb9c886a0…d918d3 (opens in a new tab) |
#9155501 | 0x39519639…6553b0 | ≈0.01 | ≈48,590 | 0x62e701a2…c5cb23 (opens in a new tab) |
#9155516 | 0x39519639…6553b0 | ≈0.01 | ≈48,590 | 0x4732cf0e…f3cb66 (opens in a new tab) |
#9155548 | 0xa499ced3…f8d45a | ≈0.01 | ≈48,786 | 0x4112e7d0…05d28b (opens in a new tab) |
This happened before: the legacy 0x839c loan
Opened 3 February 2022 · expired 7 November 2024 · active and unsafe at the pinned 18 August 2026 snapshot
8D51 borrower opened the position in this transaction (opens in a new tab) , initially borrowing approximately 5.637 WRBTC. After collateral additions and 16 liquidations, the position still owed approximately 3.6666 WRBTC.
The same wallet was first funded by B7 in the uninterrupted setup sequence that included all four 2026 borrowers. In June 2022, later February borrower and former Exchequer multisig owner 4f39 · 0x4f3948…ae2e97 sent it approximately 385,915 SOV; within 4m57s, legacy 2022 borrower 8D51 · 0x8d5158…be0fb7 allocated the same underlying amount across three loan deposits. Exact values remain in the packet.
Exact SOV handoff (opens in a new tab) · First redeposit (opens in a new tab) · Second redeposit (opens in a new tab) · Third redeposit (opens in a new tab)
- Current principal
- ≈3.6666 WRBTC
- SOV collateral
- ≈613,652 SOV
- Standalone AMM value
- ≈0.1107 WRBTC
- Modeled shortfall
- ≈3.5559 WRBTC
- Modeled coverage
- ≈3%
Dossier conclusion The same B7-linked operational cluster created material lender exposure years before the February 2026 session. Yago’s documented leadership, policy, response, and ratification roles place that exposure within his accountability record; custody and instruction records can allocate the executing key.
Yago dismissed the connection while leaving the transactions unchallenged
When the SOV-backed loan was raised, Yago answered, “No, of course not. What’s it got to do with me?” and said SOV owners could do what they chose. He later called the loan link baseless and characterized the broader exchange as “conspiratorial thinking” and “noise.” The preserved exchange contains no public commitment to require repayment, pause affected lending, pursue any available protective action, or investigate the identified positions.
Complete question and answer containing the baseless, conspiratorial, and noise response
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
Borrower-cluster value reached Sovryn’s USDt0 campaign signer
The loan record establishes the lender exposure. This separate trail follows where borrower value later reconverged: balances moved into February borrower and later RBTC hub b493 · 0xb493b1…a2c155 , that hub paid USDt0 campaign signer de169 · 0xde1690…5f6af2 current registered owner-address of the 0x924f Exchequer multisig, which also guards both Governors , and the campaign-signer wallet later sent the identified swap transaction and funded Sovryn’s USDt0 campaign.
- Borrower balances came back together. On 18 June, February borrower
91AB · 0x91ab7f…021684and February borrower5011 · 0x50110e…f07962moved nearly all of their 0.3943 and 0.4129 RBTC balances to February borrower and later RBTC hubb493 · 0xb493b1…a2c155. February borrower4f39 · 0x4f3948…ae2e97sent 0.705 RBTC to a separate hub. - Cluster hub to campaign signer. On 7 July, February borrower and later RBTC hub
b493 · 0xb493b1…a2c155sent 0.236 RBTC to USDt0 campaign signerde169 · 0xde1690…5f6af2current registered owner-address of the 0x924f Exchequer multisig, which also guards both Governor contracts . Inspect the transfer (opens in a new tab) . - Identified swap transaction and campaign funding. On 13 July, USDt0 campaign signer
de169 · 0xde1690…5f6af2sent approximately 0.234 RBTC in the transaction identified in the transaction audit as the RBTC-to-USDt0 swap. About two hours later the same wallet signed a Merkl reward-campaign transaction funding approximately 14,417 USDt0. Obtain the swap receipt/output and account ledger to complete the conversion accounting. Inspect the identified transaction (opens in a new tab) · inspect the campaign transaction (opens in a new tab) . - Merkl’s campaign page connects the funding to Sovryn’s live product. The official opportunity page (opens in a new tab) names the protocol as Sovryn, the chain as Rootstock, a 50/50 RBTC/USDT0 liquidity position, and an approximately 14,000-USDt0 reward pool. Its Deposit action links directly to the Sovryn market-making dapp (opens in a new tab) . The displayed campaign runs from 16 July through 14 September 2026.
- Displayed promotion followed. Three days later, an account displayed as FrenchVictory announced a 10% APR USDt0/RBTC migration campaign to the Sovryn community.
Borrower-cluster value reached the USDt0 campaign-signer wallet at 0xde169…, a current registered owner-address of the operational 0x924f Exchequer multisig that also guards both Sovryn Governor contracts. That same wallet sent the transaction identified as the swap and funded the approximately 14,417-USDt0 Sovryn campaign. The swap output, account ledger, and campaign authorization are the next records needed to complete the accounting trail.
9447bcb8…00dc28a. The supplied image contains no native platform metadata; the displayed date should be verified from the platform record.What RBTC lenders stand to lose
| Measure | RBTC | Meaning |
|---|---|---|
| Total lender claims | ≈29.2089 | Canonical accounting claim balance at the block |
| Pool cash | ≈21.4134 | Immediately available before redemptions |
| SOV-backed principal | ≈4.7848 | All eleven active SOV-backed positions; all unsafe |
| Estimated recovery from the identified SOV/WRBTC exchange pool | ≈0.7408 | Estimated proceeds if all SOV collateral were sold through that one reserve pool at once |
| Estimated pool-wide shortfall | ≈4.0441 | 13.8% of lender claims, assuming no borrower repayment, new capital, or outside liquidity |
| Late-lender stress recovery | ≈3.0107 | Against approximately 7.7956 RBTC remaining after cash exhaustion |
Outstanding lender exposure. The pool-wide collateral-sale estimate measures a 13.8% shortfall across all lender claims. A separate cash-exhaustion stress case measures a 61.4% loss for lenders left after earlier withdrawals consume the available RBTC, assuming zero SOV recovery and no repayment, new capital, insurance, or rescue. The located public record contains no committed cure.
Notice and response
Users warned leadership. Protection did not follow.
Victims supplied transaction hashes, balances, risk mechanics, and concrete requests. Leadership had the power to disclose, investigate, restore, pause, or support recovery. The public record shows no resulting protective commitment; liquidations and impairment followed.
The notice record joins knowledge to consequence: exact warnings were delivered, the identified routes and loans remained unresolved, and linked voting defeated the executable FeeSharing recovery.
Inspect the complete notice, response, and recovery record
8–28 March
Treasury notices
The RBTC route and total-asset warning
- Warning delivered
- Disclosures #1 and #3 published the route, balances, explorer links, and the separate November FastBTC flow.
- Power to act
- Leadership and Exchequer principals could publish the ledger, freeze further destinations, disclose the counterparty, and preserve signer records.
- Recorded response
- Yago called it overall treasury consolidation; Nahari invoked a third-party FastBTC liability.
- Missing support
- No transaction mapping or liability support was supplied; the November FastBTC flow and later 23.1464-RBTC route are distinct.
- Protection not taken
- No public exchange-account preservation, independent reconciliation, or complete current treasury statement followed.
- Continuing harm
- Victims lack a verified ledger and proceeds map; practical Exchequer liquidity remained impaired.
- Intent inference
- Organizational acknowledgment plus unsupported accounting after precise notice supports an inference of insider-directed execution.
- Records to compel
- Exchange customer-identification and account records, Exchequer instructions, FastBTC contracts, ledger, invoices, DD payees, and proceeds tracing.
March–April
Fee recovery
An unopposed signal that expired, a defeated remedy, then ratification
- Warning delivered
- The SIP-0088 signal received approximately 50,211,182 votes for and zero against, but its recorded state was Expired; it was not executed.
- Power to act
- Exchequer could restore the previous FeeSharing code and transfer administrative control; leadership could support the proposals that would make those changes.
- Recorded response
- Five B7-first-funded wallets supplied every vote against both executable proposals.
- What followed
- The final recovery was blocked despite the earlier unopposed signal and later claim of Bitocracy legitimacy.
- Protection not taken
- The contract code that began withholding fees before the vote remained in place.
- Continuing harm
- The contract still omits listed-token revenue from the accounting entries that let stakers claim fees; the Exchequer multisig retains withdrawal authority.
- Intent inference
- Outcome-determinative linked voting followed by retrospective ratification supports deliberate preservation of the disputed change.
- Records to compel
- Stake custody, delegation history at vote snapshots, voting instructions, and internal SIP-0088/0089 communications.
Part III · Blocked recovery
Recovery was blocked—and the taking was ratified later
Five B7-first-funded wallets cast every vote against two executable recovery proposals. Later, B7-origin stake supplied 99.32% of the affirmative vote for Yago’s retrospective ratification through one operational voter address.
Proposal record: SIP-0085 was created on 6 December 2024. The non-executing SIP-0088 support vote was created on 5 March 2026; the two proposals that could restore the fee contract followed on 20 March. Yago published the SIP-0089 ratification proposal on 23 March; GovernorAdmin proposal 26 was created on-chain on 17 April. Exact contract names, proposal numbers, blocks, and times are in the public packet.
SIP-0085
The BOS distribution proposal received 23.448 million votes for and 13.437 million against: 63.57% support, below the required greater-than-70%. Enough votes participated for the result to count. Without the B7-linked votes on either side, support would have been 94.95% and participation would still have remained high enough. The linked bloc changed the result.
Read the SIP-0085 forum record (opens in a new tab) · Read Sovryn’s voting rules (opens in a new tab)
SIP-0088
Five B7-first-funded wallets supplied 100% of the approximately 62,572,734 votes against each paired executable recovery proposal—about 53.5% of all votes cast and enough to determine defeat.
SIP-0089
Yago sponsored retrospective ratification. One day before the proposal, two direct B7-first-funded addresses— A738 and 9369 —delegated their voting power to 0xfEE171…4a9e7e . That address is the FeeSharing deployment wallet named in Tyrone Johnson’s official deployment record, an Exchequer signer, and the SIP-0089 proposer-voter. At the vote snapshot, the two delegated weights summed exactly to the 31,574,812.5 votes it cast for ratification.
- 99.32%B7-origin affirmative voting power
- 31,574,812.5 of 31,791,028.47 votes for
- 0.68%All other affirmative voting power
- 216,215.97 votes for, combined
What this establishes: B7-origin stake supplied 99.32% of the affirmative vote; every non-B7 source combined supplied 0.68%. The vote demonstrates near-total control of the ratification’s supporting weight through one operational voter address. Public records place Yago in sponsorship and leadership, while custody and instruction records remain necessary to allocate the private keys to specific natural persons.
A738 delegation (opens in a new tab) · 9369 delegation (opens in a new tab) · 31,574,812.5-vote transaction (opens in a new tab) · Yago’s forum proposal (opens in a new tab)
The dossier concludes that governance was not a neutral check on the disputed conduct. B7-first-funded wallets supplied every vote against executable recovery, then B7-origin stake supplied 99.32% of the affirmative weight for ratification through one operational voter address after the withholding code was already live.
Intent finding
A connected pattern of control, execution, notice, and harm
Intent is inferred from the sequence and convergence of the documented acts.
Inspect the eight facts supporting the intent finding
- Advance controlRetained owner powers, concentrated signers, B7 funding, and threshold-capable Guardian paths existed before the disputed acts.
- Undisclosed executionUsable reserves were stolen through repeated transfers; code that stole staker revenue rights went live before a governance vote.
- Coordinated timingFour linked loans opened within 15m12s, hours before Yago’s reward announcement.
- Specific public noticeVictims supplied transactions, balances, risk mechanics, named requests, and a recovery proposal.
- Dismissal and unsupported accountResponses denied relevance, attacked the inquiry, or invoked a liability without ledger support.
- Ability to mitigateLeadership, Exchequer, and governance principals had practical routes to pause, repay, restore, disclose, and investigate.
- No recorded mitigation and concentrated votingNo recorded protective commitment followed; linked voting defeated the executable recovery.
- Measurable later harmLiquidations, unsafe positions, stolen staker fee rights, stolen usable treasury assets, and an unreconciled proceeds map remained.
The combined warning, dismissal, absence of a recorded mitigation commitment, later liquidations, and impairment support the dossier’s inference of knowing disregard for lender harm. Integrated with the treasury and governance record, the dossier concludes that the course was intentional and insider-directed.
Responsibility
Who did what
Public records establish the policy, finance, and implementation roles. Key-custody and instruction records can allocate each private execution.
The leadership-to-execution chain
- 1Yago announced, justified, and sought to ratify the policy. Sovryn called him project lead (opens in a new tab) . He designed the small Exchequer framework, proposed himself as a member, announced “what we have decided” (opens in a new tab) , said the decision came before Bitocracy ratification (opens in a new tab) , and described his later proposal as ratifying it (opens in a new tab) .
- 2Tyrone authored and committed the code and deployment record. That official record names 0xfEE171…4a9e7e as sender; the wallet then deployed the FeeSharing replacement and submitted the Exchequer multisig actions on-chain.
- 3Nahari occupied the finance lane. His records cover Exchequer participation, budgets, financial reporting, and the FastBTC treasury explanation.
The sequence joins policy, implementation, and finance; custody and communications remain necessary to allocate private execution.
Published role-wallet anchors: SIP-0041 published Exchequer Committee wallet Yago role wallet · 0x428a80…bdb2be · SIP-0041 published Exchequer Committee wallet linked in the Nahari record Armando role wallet · 0xa6df7b…63f4b7 · SIP-0047 published Contracts Guardian wallet Tyrone role wallet · 0x27ae0f…1346b7
Edan “Yago” Yago
Photograph source: Strategic Bitcoin Reserve Summit speaker profile (opens in a new tab)
- Directly attributable
- Project-lead role; authorship of the approved Exchequer framework; Exchequer participation; 17 February reward pause/redirection announcement; Call #72 consolidation explanation; Call #73 responses; executive-before-ratification account; and retrospective-ratification sponsorship.
- Dossier conclusion
- Yago was the leadership, policy, management, public-explanation, dismissal, and ratification principal for the disputed sequence.
- Compel
- Instructions, board/leadership communications, borrower-key allocation, exchange account records, and knowledge of the loan timing.
Elan Nahari / “Armando Munoz”
Photograph source: Real-World Asset Summit 2025 speaker profile (opens in a new tab)
- Public Sovryn identity
- Nahari used “Armando Munoz,” shortened to “Armando” in project accounts and records.
- Directly attributable
- Co-founder and core-contributor roles; participation with Yago in the Exchequer’s executive treasury process; budget and financial-report work; first-person forum posts; and the Call #73 FastBTC account. At least eight linked files display elan@remake.money.
- Dossier conclusion
- The documentary chain places Nahari in Sovryn’s treasury accounting, reporting, budget, and explanation lane alongside Yago’s executive leadership.
- Compel
- Native account-authentication and custody records, report workpapers, general ledger, FastBTC agreements, signer instructions, and related-party records.
“Tyrone Johnson”
- Public Sovryn identity
- The pseudonym used in project, governance, source-code, and account records.
- Documented role and actions
- Publicly identified technical team lead; authored and merged the shutdown and withholding code; authored and committed the official mainnet deployment record whose artifact names FeeSharing deployment and Exchequer-submission wallet
0xfee171…4a9e7e · 0xfee171…4a9e7enamed as sender in Tyrone Johnson’s official deployment record ; published role wallet later sent and signed a Guardian rotation; an account displayed as Tyrone supplied conversion and bridge wallet8C · 0x8c9143…84f50bsupplied by the displayed Tyrone project account during the on-chain-matched May 2024 session . - Dossier conclusion
- The public Tyrone account is the documented technical and operational implementer or facilitator for core elements of the course.
- Compel
- Native Discord records, deployment logs, device/key custody, 8C continuity, DD signer identities, and the instruction chain for code and operations.
Combined responsibility finding: the transaction history establishes a centrally directed B7 operation. Yago, Nahari, and Tyrone occupy the documented leadership, accounting, and implementation chain around that conduct. Authorities should compel the custody, instruction, and communication records that assign the B7 funding wallet, borrower wallets, conversion and bridge wallet 8C, destination shared wallets DD, Exchequer multisig, and exchange actions within that chain.
The supplied 8C operational screenshots
These images show why 8C appears in the attribution record. They are displayed as context, while the transaction match—not the screenshot alone—carries the corroboration.
8C · 0x8c9143…84f50b supplied by the displayed Tyrone project account during this on-chain-matched May 2024 session and describes the same bridge and negligible-balance retry pattern independently visible on-chain. SHA-256 e9628ae8…e6a3b63. The platform’s original export and account-access record should be preserved.Part IV · Sovryn/BOS fund paths
Sovryn and BOS money used the same financial network
Public-chain records trace independently reconstructed BOS sale proceeds and Sovryn Exchequer assets through the same operations address, recurring-payment network, custody setup, and exact Bitcoin and Ethereum exchange routes. On Community Call #73, Yago acknowledged that BOS paid expenses for Sovryn and denied fund mingling nine and a half minutes later.
On two networks, independently reconstructed funds converged at the same off-ramps
On Bitcoin, at least 20.01114355 BTC attributable to a high-confidence BOS Origins collector topology reached bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5 (opens in a new tab) . All three later Exchequer pegout routes delivered 23.13948498 BTC to that exact address.
On Ethereum, BOS sale funds used 0x509201… → 0xe1D4… → 0x5f65…. Exchequer-derived DD funds later reused the exact same forwarding proxy and terminal; another DD route used a sibling proxy from the same deployment family and reached the same terminal.
- Candidate benchmark scale
- $4,169,986.84 · 85.3% of Origins’ USD-valued counter at the matched daily-VWAP benchmark.
- Exact convergence
- One Bitcoin deposit address and one exact Ethereum proxy-to-terminal route were reused across independently reconstructed BOS and Exchequer sources.
- Exchequer stablecoins reaching shared rails
- At least 411,750.640097 nominal stablecoin units reached recurring recipients or the common Gemini-labeled endpoint.
Exact deposit-address reuse is materially stronger than a generic “same exchange” label. It supports a common credited-account, merchant, or off-ramp relationship that the exchange can identify.
Community Call #73 · two statements, 9m 30s apart
Yago said BOS paid Sovryn expenses—then denied fund mingling
At 35:03, Yago said some funds were paid by BOS on Sovryn’s behalf and needed to be consolidated at the end of 2025. At 44:33, the moderator asked whether Sovryn was mingling funds with BOS. Yago answered, “No.” Hear the denial in his own voice beside the earlier statement and the shared-route evidence.
Yago says BOS paid funds on Sovryn’s behalf
Statement checked against the full call
“Some of those funds were paid out by BOS on behalf of Sovryn.”
He continued that those funds needed to be consolidated at the end of 2025 and said delaying consolidation let Sovryn maintain more liquidity in the protocol.
Hear the statement in the full Community Call #73 (opens in a new tab) · full source recording and captions checked
Asked whether Sovryn was mingling funds with BOS, Yago answers no
Excerpt checked against the full call
“No.”
Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked
The denial does not reconcile with Yago’s own cross-payment admission or the public-chain convergence. The missing records are the authorizations, separate ledger entries, project allocations, reimbursements, credited exchange accounts, and identities behind the shared wallets.
Follow every reconstructed collector, wallet, proxy, recipient, and exchange route
Multichain sale reconstruction
The candidate multichain benchmark reaches 85.3% of Origins’ sale counter
Origins records $4,888,380.30 in its USD-valued usdCollected field. Reconstructed stablecoin receipts and high-confidence Cardano and Bitcoin candidate paths produce a $3,974,628.13–$4,368,551.68 funding-day market benchmark. The daily-VWAP estimate is $4,169,986.84, or 85.3% of that counter.
Direct token paths
$432,623.93 in canonical stablecoins
The expanded reconstruction follows canonical stablecoin receipts on Ethereum, BNB Chain, Polygon, and associated collector branches. It includes the direct collector routes into 0x509201…AbD6 and labeled exchange infrastructure.
High-confidence Origins attribution
2,440,904.338471 ADA · about $1,873,923.65
Three Cardano pools contain 1,834 deposit UTXOs from 1,254 unique deposit addresses. Early pools routed to a Binance-labeled endpoint. The later controller placed an order using 277,394.921276 ADA and 36,652,194.91 BOS; the next transaction increased Minswap reserves by 277,392.171276 ADA and 36,652,194.91 BOS (opens in a new tab) .
High-confidence Origins attribution
20.01527801 BTC · about $1,863,439.26
The clean Bitcoin topology contains 297 one-output sweeps, 927 external input UTXOs, and 699 unique input addresses. Its collector rotation occurred within minutes of the independently reconstructed Cardano rotation before the balance moved to the later Exchequer deposit address.
Measurement basis: canonical stablecoins at face value and ADA/BTC receipts at matched Kraken daily low, VWAP, and high benchmarks. Bitcoin and Cardano are high-confidence Origins/Fireblocks attributions based on sale timing, unique-deposit sweep architecture, collector succession, and synchronized cross-chain rotations. Fireblocks documents the unique-address and sweep architecture (opens in a new tab) ; its vault map and the Origins order export can supply the first-party address assignment.
Central reconciliation difference: approximately $718,393.46. Accepted assets and vaults outside this reconstruction, order-time pricing, refunds, and platform accounting are the records needed to reconcile that difference.
BOS and Exchequer stablecoins reused the same Ethereum deposit route
The January Exchequer route reused the exact forwarding proxy and terminal previously used after BOS collector receipts. The March route used a sibling proxy from the same EIP-1167 deployment family and reached the same terminal.
- BOS collector lot at terminal
- ≥150,463.919739 USDT
- January Exchequer event
- ≥66,644.658655 USDT
- January + March Exchequer routes
- ≥133,809.640217 units
- 1BOS collectors and DDindependent sourcesSale proceeds and Exchequer-derived assets
- 2Same forwarding route
0xe1D4…DCd0Exact proxy reuse; sibling proxy in March - 3Gemini-labeled terminal
0x5f65…e932Credited customer or subaccount unresolved
The BOS route
0x509201 sent 200,000 USDT to the forwarding proxy (opens in a new tab) , which forwarded the exact amount (opens in a new tab) to the terminal. Balance conservation assigns at least 150,463.919739 USDT of that event to the designated collector lot.
The Exchequer routes
On 12 January, DD sent 100,000 USDT to the exact same proxy (opens in a new tab) , which exact-forwarded it to the same terminal (opens in a new tab) . On 30 March, DD sent 120,000 USDT to 0x509201; after a USDT-to-USDC swap, 122,000 USDC entered the sibling proxy (opens in a new tab) and reached the same terminal (opens in a new tab) .
Forwarding family: 0xe1D4…DCd0 , 0xF6c8…933e , and terminal 0x5f65…e932 . Gemini records can map the proxies and terminal to the customer, subaccount, beneficial owner, internal credits, trades, withdrawals, and fiat wires.
Shared custody and recurring payments
One custody and payment network served Sovryn treasury activity and BOS administration
DD received 508,947.877906 USDT reconciled to Exchequer-origin Rootstock assets. The matching DD Safes use the exact five-owner set installed on the official BOS token-owner and allocation Safes, and the same 8C address deployed both families. 0x509201…AbD6 and 0xcD9003…fBAA approved all 14 reviewed Ethereum DD executions.
Custody links
- Deployment8C created DD and the official BOS Safe family
- Shared owner setthe same five addresses control both Safe families
- Observed quorum0x509201 and 0xcD900 approved every reviewed DD execution
Payment metrics
- 277,941 USDT
- DD transfers outside the exchange routes
- 24 recipients
- every address also paid by 0x509201
- ≥244,585.603045 USDT
- strict Exchequer-derived minimum
Recorded transfers
- BOS Exchequer0.02221978958 RBTC
- Exchequer DDreconciled cross-chain assets
- DD / 509 shared railsrecipients and exchange terminals
On-chain fact
All 24 DD recipients also appear in 0x509201’s genuine USDT payment history
Twenty-three were paid by 0x509201 before DD first paid them; the remaining address was paid later. Repeated recipient batches and exact amount matches establish that DD entered an existing 0x509201 recurring-payment network.
Collective lower bound
At least 411,750.640097 units reached payees or the common terminal
The bound charges every available unrelated DD unit and the full March route dilution against the Exchequer lot before attributing any remaining amount. It avoids adding overlapping subset bounds.
Controller attribution
Organizational roles are visible; most human key holders remain unresolved
Yago and Nahari are connected through documented management, finance, policy, and public-explanation roles. Tyrone is tied to 8C through the preserved supplied account record and on-chain-matched session. The public record identifies 0x509201 as a shared operations address; its natural-person controller remains unidentified.
- Separate funding described
Yago said Sovryn had not funded BitcoinOS and that Sovryn’s treasury was not being requested.
- A large contribution path described
He said Sovryn would need to invest or provide $5 million–$100 million in value or in-kind support (opens in a new tab) for its 10% BOS interest.
- Broad contributions authorized and acknowledged
SIP-0083 (opens in a new tab) described substantial prior Sovryn contributions and further technical, audit, marketing, infrastructure, and network-operation support.
- Cross-payments acknowledged; mingling denied
Yago said BOS had paid obligations on Sovryn’s behalf (opens in a new tab) , then answered “No” (opens in a new tab) when asked whether the projects were mingling funds.
Accounting and legal inquiry
Cross-project value transfer
Why the shared routes support an embezzlement and related-party-diversion inquiry
The public record now establishes more than shared personnel. Sovryn assets entered custody and payment infrastructure controlled by the same owner-address set used for official BOS administration; BOS collector-wallet funds and Exchequer-derived assets converged at exact exchange routes; and 0x509201 both received and approved payments from the shared DD Safe.
The Exchequer assets were liquid BTC, stablecoins, ETH, and BNB. Yago described Sovryn’s BitcoinOS interest as 10% of BOS supply. A token allocation has different liquidity, control, vesting, revenue, and economic rights from liquid treasury assets. Fair-value analysis requires the BOS allocation’s custody and vesting terms, its realizable value at each transfer date, BTC OS Limited’s cap table and revenue rights, and the consideration Sovryn received for every contribution.
Dossier conclusion: these facts support investigation of whether Sovryn property was diverted to BitcoinOS, related parties, or personal benefit without valid authority, fair consideration, complete disclosure, or reimbursement.
- On-chain facts
- Shared Safe owners, concentrated approvals, recurring payees, wallet-level pooling, and exact Bitcoin and Ethereum off-ramp reuse.
- High-confidence Origins attribution
- The Bitcoin and Cardano pool assignments are supported by sale timing, unique-deposit sweep topology, collector rotation, and cross-chain synchronization. Origins and Fireblocks hold the confirming vault map.
- Purpose and beneficial ownership
- Invoices, project codes, exchange KYC, trades, withdrawals, intercompany entries, and payee identities allocate what the transfers purchased and who received the economic benefit.
- Embezzlement referral
- Investigators should trace authority, accounting treatment, purchased work, reimbursement, and ultimate benefit—and identify whether any Sovryn property financed BitcoinOS or a related party without fair value returning to Sovryn investors.
Priority records: Origins/Fireblocks order and vault exports; Gemini and other exchange address-assignment, KYC, trade, withdrawal, and bank files; Sovryn and BTC OS Limited general ledgers and due-to/due-from accounts; DD/509 payee identities, invoices, payroll, and project codes; Exchequer budgets and approvals; BOS allocation valuation and custody; and private-key and instruction records for the shared owners.
Next: the sale claims and technical audit. The fund-flow record answers where reconstructed sale proceeds went and fixes the scale of the solicitation. Part V compares what BOS purchasers were told with the public bridge and code available while those funds were raised. Read the sale-claim audit.
Part V · BOS sale claims
BOS was sold with trustless-bridge claims while the public bridge was unfinished
Origins records 609,509,366.81 BOS sold and $4,888,380.30 in its USD-valued amount-collected counter. During that sale, official materials described trustless Bitcoin bridging without a multisig or federation. The public product was one-way and used valueless test assets; the reviewed public code implemented a two-party optimistic verifier and left the complete production bridge unfinished.
What the audit found
The reviewed public code implemented a two-party optimistic verifier; the advertised bridge additionally required custody, multiparty, two-way, recovery, and liquidity components. Think of BitSNARK less like a vault that automatically rejects a false withdrawal and more like a timed alarm-and-dispute system: an informed, funded watcher must detect a bad claim and complete the required Bitcoin challenge before the deadline.
- Public artifact
- The repository contained a two-party proof checker and dispute prototype. The marketed bridge required additional custody, multiparty, two-way, recovery, and liquidity systems.
- Where trust remains
- If no effective challenge completes, a false claim can reach the claimant path under the stated timeout and transaction conditions. Pre-signing adds a separate trust condition: a mandatory signer must never approve a hidden alternative, and after the allowed transactions are signed, at least one of the two required signing capabilities—and every copy or backup of it—must become permanently unusable. Bitcoin cannot verify either fact.
- What was publicly available during the sale
- The 16 February launch used valueless test assets and moved one way from Bitcoin Testnet 3 to EVM testnets. BitcoinOS described the return prover, two-way path, multiparty verification, and Grail code as future work while the sale used present-tense “trustless” claims.
The findings show a concrete gap between categorical no-counterparty marketing and the conditional public design. That substantiation gap warrants investigation into whether sale-linked descriptions gave purchasers a misleading or incomplete impression.
What purchasers were told
On 29 January 2025 (opens in a new tab) , Edan Yago said BTC could move across chains trustlessly “without having to use a multisig or a federation.” A 19 February paid promotion (opens in a new tab) quoted him saying users could experience “truly trustless Bitcoin bridging.”
The 27 February sale page (opens in a new tab) said BitcoinOS enabled any blockchain to connect with Bitcoin trustlessly and placed that representation beside BOS purchases and possible annual revenue flows above $7 billion. The 3 March sale notice (opens in a new tab) repeated the trustless claim with a purchase call to action, escalating stages, bonuses, referrals, and a $50 minimum.
What was publicly available during the sale
The 16 February launch record (opens in a new tab) described valueless test assets, a one-way Bitcoin Testnet 3-to-EVM path, and a return prover and two-way bridge still being built. The reviewed repository described a local two-party regtest demo while multiparty verification, two-way operation, and Grail code remained future work.
Origins’ two completed backend periods record the full launchpad sale. The first completed period (opens in a new tab) and its post-maintenance continuation (opens in a new tab) record 609,509,366.81 BOS in tokensSold and $4,888,380.30 in the USD-valued usdCollected counter across accepted crypto assets. The first period includes the issuer’s $2.225 million Phase 1 result (opens in a new tab) ; the displayed total is the sum of the two completed periods.
Measurement: first-party Origins API counters. Audited net proceeds and the composition of purchased, bonus, referral, and staker allocations require issuer, banking, and subscription records. The sale-total record preserves both periods, exact decimals, response snapshots, scope, and exclusions.
The sale claims, in Edan Yago’s and Gadi Guy’s own words
Hear the representations before inspecting the technical record beneath them. The recordings establish what was said; the code, symbolic model, signature rules, and bounded lab record establish what the public system could substantiate.
Yago says Bitcoin can have “truly trustless” layer twos
Excerpt checked against the full source recording
“It allows Bitcoin to have truly trustless layer twos—rollups where any type of functionality can occur.”
Watch the full BitcoinOS presentation on YouTube (opens in a new tab) · source recording and captions checked
Yago presents Grail as cross-chain BTC without a multisig or federation
Excerpt checked against the full source recording
“take BTC and move it across chains trustless, without having to use a multisig or a federation.”
Watch the full BitcoinOS keynote on YouTube (opens in a new tab) · source recording and captions checked
Guy says BitSNARK enables trustless bridges without counterparty risk or a person or group able to steal funds
Excerpt checked against the full source recording
“There is no person or—or group of persons who together can steal your money.”
Watch the full Bitcoin Magazine NL interview on YouTube (opens in a new tab) · source recording and captions checked
Later acknowledgments: in April, Guy said Grail still needed productionization (opens in a new tab) . In June, Yago acknowledged additional trust assumptions (opens in a new tab) . Those statements confirm conditions omitted from the categorical sale language.
Inspect the detailed BOS sale-wallet and cross-project control record
Sale proceeds · wallet reconstruction
Detailed Ethereum BOS collector and downstream-route record
Origins’ unique-deposit-address model (opens in a new tab) left a repeatable on-chain fingerprint. Exact buyer payment, deposit-address sweep, common gas funding, published stage price, collector succession, and official vesting-beneficiary matches identify three rotating primary Ethereum collectors with high confidence. The same method also identifies a smaller associated branch at 0x60c507….
A sale gas wallet activated isolated deposit addresses with 0.001 ETH. Each address received a participant’s canonical token and swept the identical raw amount into a collector. The early gas wallet funded the middle gas wallet (opens in a new tab) and the later multichain gas wallet (opens in a new tab) ; the middle wallet also funded the later one (opens in a new tab) . This links all three primary collector generations independently of address labels. The 60c branch adds five exact payment-and-sweep pairs through four new deposit addresses. (opens in a new tab) The full reconstruction contains 144 exact purchase sweeps across 127 participant deposit addresses; forty-three payment-source addresses also appear as beneficiaries in the official Community Sale vesting record. These are discovered lower bounds because Origins permitted exchange deposits and separate payment and claim wallets.
-
01 · Early BOS Ethereum collector
0xBb55bB…243243- Exact sweeps
- 79
- Deposit addresses
- 68
- Payer = beneficiary
- 22
3 Mar 2025–12 May 2025. Gas funder
0x528D59cA…d6753a. -
02 · Middle BOS Ethereum collector
0xFeD3a5…fF0628- Exact sweeps
- 27
- Deposit addresses
- 26
- Payer = beneficiary
- 8
13 May 2025–30 Jun 2025. Gas funder
0x8bb0d983…e23c7a. -
03 · Post-maintenance multichain BOS collector
0x1160A7…abf08C- Exact sweeps
- 33
- Deposit addresses
- 29
- Payer = beneficiary
- 14
10 Jul 2025–22 Oct 2025. Gas funder
0x64f842e5…c2afa3.
Other verified chains: the same 1160 collector also received participant-specific deposits on Arbitrum (opens in a new tab) —about 3,841 ARB and 0.191 ETH—and Polygon (opens in a new tab) —about 1,335 USDT and 389 POL. The Arbitrum balance moved to one unlabeled address; the reviewed Polygon record establishes receipt but no onward destination. Exact values remain in the wallet-flow record.
Early collector · exchange endpoint
About $102,167 in canonical stablecoins, plus WBTC and ETH, reached Binance 14
BB55 moved pooled balances through 0x6C250D…6038. That relay sent 102167.018527 USDT/USDC/DAI units, 0.00274432 WBTC, and 27.157479067347059439 ETH into the publicly labeled Binance 14 address. Inspect the route. (opens in a new tab) The credited customer account is identifiable from Binance and Fireblocks records.
Middle collector · project operations
Middle-period assets reached both an operational wallet and 0x509201 directly
FeD3 sent 43585.792331 USDT/USDC units and 5.799965340728752 ETH to 0x4ad662…D4a. That wallet was first funded by 0x509201…AbD6 (opens in a new tab) and later sent 23,000 USDT and 5,000 USDC (opens in a new tab) back. FeD3 also sent 4937.393862 canonical stablecoin units, 0.001 WBTC, and 1.196003859314349906 ETH directly to 0x509201 (opens in a new tab) . It and 1160 later reused the early Binance relay (opens in a new tab) . The pooled 4ad account requires its internal ledger to assign each payment after receipt.
Post-maintenance collector · direct 0x509201 route
About $234,160 in stablecoins and 3.6055 ETH went directly to the shared operations address
On 14 November 2025, 1160 sent 204103.50752 USDT (opens in a new tab) , 30056.588245 USDC (opens in a new tab) , and 3.605528140408725578 ETH (opens in a new tab) to 0x509201…AbD6 . That address already links B7, Sovryn’s official Ethereum bridge, DD, and the official BOS Safe family.
0x509201 moved most of the 14 November collector-wallet stablecoin lot
Two primary reconstructed collector wallets sent $238,982.49 in USDT and USDC face value directly to the shared operations address on 14 November 2025. By 30 November, balance conservation establishes that at least $226,480.57—94.77% of that designated lot—had left.
- Received
- $238,982.49
- Minimum moved
- $226,480.57
- Labeled exchange endpoints
- ≥$183,433.94
- 1 Identified BOS collectors $238,982.49 USDT and USDC sent directly
- 2 Shared operations address
0x509201…AbD6Funds pooled before dispersal - 3 Gemini · Kraken · Coinbase at least $183,433.94 Reached publicly labeled exchange addresses
Why the lower bound is certain
The calculation first assigns every outflow to the wallet’s pre-existing and other available stablecoins. Only the remainder is assigned to the collector lot. This produces a source-neutral minimum even though token units become fungible when pooled.
The first-hop bound is $183,441.68. After deducting 4.743054 of swap loss and 3 USDC already in the Kraken relay, at least $183,433.94 reached the publicly labeled exchange addresses.
The clearest route ends at Gemini
0x509201 sent exactly 200,000 USDT to an EIP-1167 proxy in a publicly labeled Gemini deployment system (opens in a new tab) ; on 25 November the proxy sent the exact amount to the address publicly labeled Gemini 4 (opens in a new tab) . Since the wallet held only 49,536.080261 USDT before the collector receipts, more than $150,463 of that deposit had to come from the designated lot. Routes ending at publicly labeled Kraken (opens in a new tab) and Coinbase (opens in a new tab) addresses raise the strict exchange-endpoint minimum to $183,433.94.
BNB Chain followed a different path
The same known collectors sent $7,857.87 in USDT and USDC to the same address (opens in a new tab) . The complete canonical-token history contains no later non-zero outflow (opens in a new tab) , and current balances exceed the traced receipts. That lot remained conserved at 0x509201 through the research cutoff. The separately identified 60c Origins branch swept another 202.9888302 BSC stablecoins and 2.346967086497769 BNB to 0x509201 (opens in a new tab) ; assigning those BNB-side receipts to individual orders requires the Origins ledger. A separate FeD3 route sent about $20,638.70 through the reused relay to a publicly labeled Binance wallet (opens in a new tab) .
This calculation isolates the earlier Ethereum and BNB stablecoin slice
The matched canonical-stablecoin face value equals 6.29% of Origins’ $4.89 million usdCollected counter; the expanded canonical-stablecoin reconstruction in this earlier record reaches 7.04%. The current multichain reconstruction above adds Cardano, Bitcoin, and later-discovered canonical stablecoin paths and supersedes this slice as the sale-wide coverage measurement.
TGE and vesting record
The official Community Sale vault created 1,162 cancellable schedules
The Ethereum vault (opens in a new tab) created schedules for 1,141 beneficiaries totaling 351,227,296.06 BOS. That equals 57.62% of Origins’ tokensSold counter. The remaining 258,282,070.75 BOS requires reconciliation across late wallet submissions, other distribution paths, cancellations, bonuses, and the complete order ledger.
Administrative power
The same BOS owner Safe holds forfeiture and salvage authority
Every decoded schedule is cancellable. An emergency cancellation of two schedules (opens in a new tab) moved 496,028.63 BOS of unclaimed vested and unvested principal to the official BOS owner Safe, which forwarded the same amount to the original vault deployer in the same batch. That owner Safe uses the five-address control set shared with DD.
Investor diligence
Cross-project control risk
Detailed BitcoinOS operational and bridge-control risk record
BitcoinOS identifies Edan Yago as co-founder and CEO and Elan Nahari as co-founder and COO (opens in a new tab) . The 2025 BTC OS Limited MiCA filing (opens in a new tab) lists Yaron Edan Yago as the only named management-body member and says the company issues and supports BOS and coordinates contributors. On-chain records identify part of the shared infrastructure: the DD wallets that received Sovryn treasury-derived assets have the same five-owner set and 8C deployer as the official BOS token-owner and allocation Safes. The same two addresses repeatedly operated DD and appear throughout the BOS Safe family. Inspect the cross-project custody record above. The natural persons behind those owner addresses and the allocation of DD’s payments between projects remain unidentified.
Protective judgment: until those controls are published and independently verified, users should not entrust BTC to a BitcoinOS bridge or treat “trustless” as an operational fact or a reason to buy BOS. Test claims with valueless assets; do not substitute founder reputation or operator count for verifiable control separation.
- Documented Sovryn conduct and harm
- This dossier characterizes the treasury transfers and the taking of stakers’ fee rights as theft. It documents Yago as the leader who announced and defended the policy, dismissed the lender warning, and sponsored its ratification; it places Nahari in an Exchequer finance, accounting, and reporting lane. It also documents five B7-first-funded wallets casting every vote against two executable recovery proposals, 99.32% B7-origin support for later ratification, liquidations, and lender exposure. The located record contains no leadership commitment to require repayment, pause affected lending, pursue any available protective action, or independently investigate the loans after users disclosed the danger. This is the dossier’s evidence-based theft finding; authorities and courts determine criminal charges and liability.
- Why borrowing against SOV matters
- Borrowing RBTC against thinly traded SOV obtained bitcoin liquidity without an immediate market sale and transferred collateral-liquidity risk to the lending pool. At the measured snapshot, selling all eleven loans’ SOV collateral through the only identified pool under the stated assumptions left an estimated 4.0441-RBTC shortfall. The pattern warrants examination as an exit-risk scenario: it converted SOV exposure into RBTC liquidity while leaving lenders with residual collateral-liquidity risk. The B7-linked borrower cluster remains pseudonymous; authorities should compel key-custody and communications records to identify its controllers and motive.
- The protective test for “trustless”
- A bridge is meaningfully independent of leadership only if users’ BTC remains safe and redeemable when any founder, company officer, software publisher, operator, or custodian becomes dishonest, compromised, or unavailable. Reputation is not a security control. Independent beneficial control must be verified through ownership, key-custody, infrastructure, and instruction records; counts of addresses, keys, or operators are insufficient.
- Sale-period BitSNARK control surfaces
- The reviewed design depended on a capable watcher completing a funded challenge before timeout, correct setup and transaction graphs, no unauthorized alternative being signed during setup, both required script-path signing capabilities not remaining jointly available, and the discrete log for the configured Taproot internal key remaining unavailable. Under the stated premises, an invalid claim can reach the claimant path if no effective challenge confirms; if both required script-path signing capabilities survive, their holders can co-sign a fresh alternative spend through the locked-funds leaf. BitcoinOS should produce the key-generation, erasure, custody, backup, and instruction records that identify who held each capability and whether every disallowed path became unavailable.
- Later Grail Pro control surfaces
- BitcoinOS’s later architecture (opens in a new tab) uses TEE-held operator keys, mutable rosters and thresholds, and a documented 12-of-16 example. Twelve effective authorities can authorize a release; five refusals or outages leave only eleven and block the normal path. The page’s statement that twelve compromises are required for “loss of service or funds” is therefore wrong for service availability:
16 − 5 = 11 < 12. A mandatory custodian policy (opens in a new tab) can give that custodian a veto over its BTC. “Twelve authorities” is a threshold count; independence requires separate beneficial controllers, infrastructure, update paths, and recovery powers. - Frontend and software-publisher risk
- BitcoinOS’s own trust model says users trust the frontend (opens in a new tab) , which queries operator keys to generate Taproot deposit addresses. Its operator instructions use the mutable image tag
grailpro/cosigner:latest(opens in a new tab) , not a pinned digest. A substituted roster or address could send a deposit outside the intended quorum. The tag can change what a later pull resolves to; if operators deploy it and the admission policy accepts it, one shared faulty or malicious release could affect nominally separate operators. The reviewed record leaves the referenced frontend audit, expected enclave measurement, immutable image digest, update approver, release history, allowlist, attestation log, and controller unidentified. - Company-level access and loss terms
- A pinned public Grail frontend source file (opens in a new tab) contains terms that call BTC OS Limited the “Bridge Operator,” say reverse redemption is supported only where technically feasible, warn of partial or total loss, and reserve company discretion to suspend or restrict access. BitcoinOS should produce the versioned deployment, presentation, acceptance, custody, and service-access records that establish when those terms operated and who exercised the reserved authority.
- Records still needed
- Before anyone relies on “trustless” or “decentralized,” BitcoinOS should publish the production operator and custodian roster; legal and beneficial-controller mapping; vault addresses and scripts; key-generation and erasure evidence; internal-key custody; challenger funding and data plans; roster, threshold, software, emergency, and recovery authority; reproducible source and build hashes; TEE measurements and approval logs; independent audits; incident history; and BOS source-and-use-of-funds accounting.
Inspect the full technical proof and claim chronology
Technical terms, translated
- Zero-knowledge proof
- A cryptographic proof of a statement defined by a circuit, verification key, and public inputs. Bitcoin custody and release require separate mechanisms.
- Optimistic verification
- The complete proof is checked outside Bitcoin. Bitcoin adjudicates a disputed computation only when someone challenges in time.
- One-of-N honesty
- Safety depends on at least one watcher having the correct data, funds, and time to complete every required challenge transaction before the deadline. Being honest is not enough if the challenge is never confirmed.
- Pre-signing and key erasure
- Participants sign the allowed future transactions before funds are locked. “Erasure is a premise” means security assumes no hidden alternative was signed and that enough signing power—and every copy or backup needed to restore it—then became permanently unusable. Bitcoin can verify the signatures, but not either off-chain fact.
- Safety versus liveness
- Safety asks whether an invalid claim can release funds. Liveness asks whether an honest user can complete a withdrawal.
- TEE
- A protected hardware environment—documented for later Grail Pro as AWS Nitro—relied on to run approved code and protect keys.
The counterexamples and their premises
A universal security claim fails when one permitted adverse execution exists. BitcoinOS’s own transitions and script supply the protocol premises; a separate valueless Core lab run tests only the analogous threshold-signature principle.
The published symbolic model lets ProofUncontested consume Locked Funds without consulting IsProofValid. An audit patch specializes the model’s fixed CHOOSE expression to false and adds a strong label-preservation invariant. TLA+ TLC returned this three-state symbolic trace:
- InitLocked funds exist.
- ProofThe prover publishes an invalid asserted result.
- ProofUncontestedThe locked-funds label disappears into the prover path.
Result and premises: TLC proves symbolic reachability in this abstract model. Applying that trace to Bitcoin requires a matured timelock, unspent inputs, an available valid presignature, no effective challenge, and confirmation of ProofUncontested; CSV time, signatures, value, ownership, recipients, and Bitcoin consensus sit outside the model.
The intended locked-funds Tapscript leaf checks one prover signature and one verifier signature. It contains no proof predicate or opcode-level output covenant. Its acceptance condition reduces to:
Accept(T) = Verify(pkP, sigP, T) ∧ Verify(pkV, sigV, T)
Taproot SIGHASH_DEFAULT binds the transaction outputs, so old signatures cannot simply be copied to a changed recipient. But if both signing capabilities survive—or both parties pre-sign that exact alternative before erasure—they can authorize it. The finite coalition model finds 1 authorizing coalition out of 4, with a minimum of 2 capabilities.
Result and premises: the intended script leaf permits the two holders to authorize a fresh spend if both signing capabilities survive. The whole P2TR output also has a configurable internal-key path. Safety therefore relies on a correct finite graph, output-binding signatures, an unavailable internal-key discrete logarithm, and effective deletion or non-retention of at least one of the two required script-path signing capabilities.
An isolated Bitcoin Core v31.1 regtest used P2WSH/ECDSA, legacy OP_CHECKMULTISIG, and SIGHASH_ALL. It accepted and mined a prescribed two-of-two spend. Copying the signatures onto a changed recipient failed; freshly signing that alternative with both retained keys succeeded; one signature failed.
Lab scope: the experiment establishes the output-binding and retained-key proposition in a generic P2WSH/ECDSA analogue. Exact BitSNARK P2TR/Tapscript/Schnorr replay remains unreproduced, and the public packet lacks a deterministic replay fixture. Bitcoin verifies signatures and transactions, not erasure. A public, independently audited setup and custody record can provide evidence of deletion; it cannot rule out a hidden copy or secretly pre-signed alternative.
Verified capabilities in the public code
The reproduced public result was an optimistic verifier prototype. The bridge marketed to purchasers also required custody, networking, redemption, recovery, and liquidity systems.
Reproduced successfully
- v0.1: 56 of 56 public tests passed.
- v0.2: TypeScript compiled; 154 tests passed and two were skipped.
- The separate decoder test verified its supplied Groth16 witness.
- The public code implements a real two-party optimistic dispute prototype.
Capabilities absent from the reproduced results
- The only Circom statement in the reviewed v0.2 tree was a fixed multiplier test, not dynamic bridge inclusion, burn, amount, or recipient data.
- The repository contained no executable two-way Grail custody, mint/burn, redemption, operator, recovery, or liquidity system.
- A Jest end-to-end test was skipped, while a separate Docker-dependent local two-party regtest demo remains unreproduced; this audit therefore contains no reproduced networked multiparty two-way bridge result.
- Any private prototype sits outside the reviewed public tree and requires production source, build, audit, and deployment evidence for assessment.
Later Grail Pro documentation confirms a different conditional trust model
Grail Pro is a later architecture, separate from the sale-period design. Its first-party documentation shows a production-facing system dependent on institutional operators, protected hardware, and threshold authorization—not ZK alone.
The documented 12-of-16 example
BitcoinOS’s architecture (opens in a new tab) says operators verify proofs in AWS Nitro enclaves and authorize Bitcoin releases through a threshold. A dated article (opens in a new tab) gives twelve signatures out of sixteen as its example.
- Minimum effective signing coalition
- 12 of 16
- Authorizing subsets, including supersets
- 2,517
- Minimum refusals that block the normal threshold path
- 5
- If a distinct custodian is also mandatory
- 13 minimum; custodian alone can veto
- If the custodian is one of the 16
- 12 including it; custodian alone can veto
Deployment scope: custodian membership remains ambiguous, so both cases are shown. Authority counts and human counts are distinct: enclave isolation could require separate compromises, while common build, attestation, roster, cloud, recovery, or implementation control could affect many. The minimum human coalition remains indeterminate until BitcoinOS publishes the topology, beneficial-control map, and reproducible Grail Pro code. These figures count logical coalitions rather than probabilities.
An expert warned Yago months before the sale
On 24 July 2024, Weikeng Chen challenged whether the announced mainnet result supported the covenant and bridge claims being made and urged Yago to scrutinize what his technical team had told him. The later audit confirms the core concern: the public record showed a proof-verification milestone, not a completed public two-way trustless bridge.
What Chen warned about—and what the code shows
- The warning: after a participant linked the BitcoinOS announcement, Edan Yago said BitcoinOS had done it on mainnet (opens in a new tab) . Chen challenged the covenant claim (opens in a new tab) and urged Yago to scrutinize the technical team’s representations (opens in a new tab) .
- The audit’s central finding: the identified transaction supports a real proof-verification milestone, but the reviewed public code was a two-party optimistic verifier—not a completed, public, two-way bridge that removed counterparty trust. Its safety depended on a timely challenger, correct setup, a complete pre-signed transaction graph, no complete signing coalition remaining available, no secretly pre-signed alternative, and an unavailable Taproot internal-key discrete logarithm.
- The later audit: Chen challenged the mainnet covenant claim and warned Yago to scrutinize his technical team’s representations. The audit found the same substantive gap: the public artifact was a two-party optimistic verifier whose safety depended on off-chain setup, key deletion, and active challenge—not the completed trustless bridge later marketed beside the BOS sale.
- Relevance to the BOS sale: trust, setup, challenge, and implementation scope were disputed publicly months before categorical bridge statements were used to promote BOS. The thread establishes contemporaneous notice; the code audit independently establishes the substantiation gap.
Method: Telegram supplies the dated warning and Yago’s response. Pinned source code, executable tests, an audit-patched symbolic TLA+ trace, finite coalition arithmetic, Bitcoin’s signature rules, and the bounded Core lab record supply the technical conclusion independently.
6730ea2e…219ac6.
c6f38239…ea32.Preservation boundary: the public message pages corroborate the displayed sequence, authors, UTC dates, and reply chain. A native Telegram Desktop export would still be the strongest record for deleted, edited, service, or media content.
| Date | Public representation or event | Verified technical or sale record |
|---|---|---|
| 23–24 Jul 2024 | BitcoinOS reported a BitSNARK mainnet demonstration (opens in a new tab) ; Yago called it done on mainnet; Chen publicly challenged the implementation and claim scope | The identified transaction and decoder establish a proof-verification milestone. A complete dispute graph and public two-way bridge remain unreconstructed, and the design adds active-challenger and setup assumptions |
| 29 Jan 2025 | Yago promoted moving BTC across chains without a multisig or federation | The pinned v0.1 baseline placed networked multiparty operation and a two-way peg in future work |
| 16–19 Feb 2025 | One-way valueless testnet (opens in a new tab) followed by a paid promotion for “truly trustless” bridging | The product record still described a return prover, two-way bridging, and mainnet delivery as future work |
| 26–27 Feb 2025 | A repository snapshot carries 26 February Git metadata; the direct presale page (opens in a new tab) followed on 27 February | The snapshot described a local two-party regtest demo and future multi-verifier/two-way work; public availability on 26 February requires hosting or release evidence |
| 3 Mar 2025 | The BOS sale opened (opens in a new tab) with categorical trustless-bridge language and a direct purchase call to action | The public bridge remained unfinished and one-way on valueless test assets |
| 20 Mar 2025 | “Fully production-ready” attributed to Yago (opens in a new tab) | The same-day issuer post (opens in a new tab) described a basic two-party regtest release and future multiparty/Grail work; exact scope remains unresolved |
| 14–24 Apr 2025 | Guy said no person or group could steal funds; BitcoinOS reported $2.225 million raised in phase one (opens in a new tab) | The same interview said Grail still needed productionization; purchaser-level exposure and reliance require account, communication, and allocation records |
| Jun–Sep 2025 | Yago acknowledged additional trust assumptions (opens in a new tab) | The MiCA paper (opens in a new tab) called Grail trust-minimised and planned a further audit before production |
| 3 Mar–22 Oct 2025 | Two completed, contiguous Origins backend periods (opens in a new tab) covered the full launchpad sale | $4,888,380.30 in the USD-valued usdCollected counter and 609,509,366.81 BOS in tokensSold; the Phase 1 report falls within the first period |
Established findings
- Technical conditions: rejecting an invalid claim requires an effective challenge to complete in time. Constraining spends to the approved graph separately requires that no unauthorized transaction was pre-signed, the two script-path capabilities do not remain jointly available, and the Taproot internal-key discrete logarithm remains unavailable.
- Substantiation gap: categorical bridge claims accompanied a sale while the public product was one-way/testnet and public two-way, networked, multiparty bridge components remained unfinished.
- Fundraising measurement: Origins supplies first-party platform counters across two completed periods. Audited net receipts and the allocation breakdown require issuer, banking, and subscription records.
Records authorities should compel
- Archived marketing, terms, disclosures, and code versions delivered to each purchaser
- Marketing approvals, technical reviews, and communications showing what each speaker knew and intended
- Dated private code, builds, audits, and deployment records claimed to support each sale-period statement
- Purchaser exposure, deposits, allocations, token disposition, reliance, causation, and loss records
- Corporate attribution, agency, jurisdiction, and records required for a final legal finding
Conclusion: taken together, the dated sale claims, public implementation limits, first-party fundraising counters, and reconstructed proceeds routes support focused investigation into what purchasers were told and how their payments were controlled and used. Audited net receipts, knowledge, reliance, causation, and loss require the private records identified above. Read the full proof, dated claim matrix, sale-total record, wallet-flow record, and 0x509201 follow-through record.
Transition to recovery: the record now joins the sale claims, the system’s technical conditions, the reconstructed money paths, and the full Origins counter. Part VI identifies the purchaser, platform, code, key-custody, exchange, and accounting records needed for attribution and recovery.
Part VI · Recovery
Preserve evidence. Trace the money. Pursue recovery.
This record is built for action. Victims can document losses, reporters can verify the central claims, and investigators can preserve platform and exchange records before they disappear.
For victims
Preserve the statements and promises you relied on, along with wallet exports. Calculate deposits, withdrawals, rewards, and remaining exposure. Record the steps you took to limit harm, and submit only copies through the encrypted intake. Never submit a seed phrase, private key, or password.
Submit evidence securelyFor reporters
Start with the concise media brief, chronology, transaction set, statement-versus-record exhibits, reproducible datasets, and source index. Ask named principals for document-backed answers to the compulsory-record requests.
Read the media brief Download the full evidence packetFor authorities
Preserve exchange, platform, BitcoinOS marketing, code, bridge-control, and BOS purchaser records immediately; identify the people controlling the five shared DD/BOS owner addresses and the borrower keys; obtain the missing Sovryn/BTC OS Limited intercompany ledgers, DD payee file, and FastBTC file; trace centralized-exchange and related-party proceeds; and interview the named policy, accounting, and implementation principals.
Review records to preserve and obtainRecords authorities should preserve and obtain
- Immediate preservation of forum, Discord, GitHub, Google Drive, email, device, and cloud audit logs
- Natural-person and beneficial-controller identity, key custody, devices, backups, and signer logs for the 0x924f Exchequer multisig, Contracts Guardian shared wallet, B7, borrower wallets, 8C, D9, and all five shared DD/BOS owner addresses
- Centralized-exchange customer-identification and complete account activity for the exchange-style Bitcoin deposit and consolidation route
- Sovryn and BTC OS Limited board, leadership, committee, budget, invoice, payroll, vendor, general-ledger, journal-entry, intercompany-account, reimbursement, cost-allocation, bank, exchange, and tax records
- FastBTC lender/provider contracts, liabilities, approvals, wallets, and payment mapping
- FeeSharing tickets, code-review messages, deployment logs, instructions, and vote planning
- Borrower communications, custody logs, repayment discussions, risk review, and liquidation response
- BitcoinOS bridge-key, operator, custodian, roster, threshold, software-allowlist, code, build, audit, deployment, incident, and recovery records
- Origins and Fireblocks deposit-address, vault, sweep, workspace, API-user, policy, signer, and audit logs; Binance records for the identified relay account and later withdrawals
- BOS purchaser exposure, deposits, allocations, token disposition, reliance, causation, loss, related-party, fundraising, and source/use-of-funds records
- DD recipient identities, invoices, payroll and vendor purpose, project allocation, approvals, beneficial ownership, current custody, and subsequent asset disposition
- Victim reliance, deposits, stakes, lending claims, withdrawals, rewards, cost basis, and damages
Appendices A–C · publication record Inspect the full record Open the chronology, call evidence, source index, exhibit index, and publication status.
Record files
Open the reproducible datasets and publication materials directly, or continue into the complete appendices below.
Appendix A
Case chronology
A compact sequence for referrals and reporting. Each current-state number remains tied to its own block.
A shared wallet requiring two of three owner approvals sent 5.9 RBTC to common funding wallet B7
The transfers identify the shared wallet that funded B7 and the approving wallet addresses. Obtain account, signer, device, and instruction records to identify the people behind those approvals.
B7 funded a rapid setup batch of linked wallets
Ten newly used wallets sent their first outgoing transaction directly back to B7 73–380 seconds after B7 funded them. The timing and common destination establish a centrally directed setup session.
The Exchequer multisig held both FeeSharing administrative powers
The power to replace the FeeSharing code and the power to operate it remained with the Exchequer multisig at 0x924f. No later transfer of either power to a Bitocracy-controlled delayed-execution contract was found in the contract history.
Legacy borrower wallet 8D51, first funded through B7, opened the SOV-backed RBTC loan
After later collateral additions and 16 liquidations, this earlier loan remained active, unsafe, and deeply undercollateralized at the pinned August 2026 snapshot. It shows that the linked lending pattern began four years before the February 2026 loans.
February borrower wallet 4f39 transferred exactly 385,915 SOV to legacy borrower wallet 8D51, which put the full amount into three loans
The exact amount moved from the later February borrower to the legacy borrower and into the loans within 4 minutes 57 seconds, directly linking their operations.
A project Discord account displayed as Tyrone supplied the address of conversion-and-bridge wallet 8C during a live bridge session
Same-day public BOB transactions match the address, tokens, small test amounts, failure and retry, and final transfers shown in the conversation. Obtain the native Discord account and message records to authenticate the account and preserve the full exchange.
Yago publicly described BitcoinOS as separately funded and said Sovryn had not funded its development
Yago wrote that Sovryn had not funded BitcoinOS, called the developer team self-funded, described separate contributors and funding, and said Sovryn's treasury was not being requested. He repeated the current-funding distinction on Community Call 63.
Yago described the value and fundraising contribution contemplated for Sovryn's 10% BOS allocation
Yago said that, for Sovryn to receive 10%, it would need to invest between $5 million and $100 million in value or provide in-kind value to that degree; he also said Sovryn was expected to engage actively in raising BOS funds. This is a contemporaneous qualification to the June separation statements.
Official Sovryn records acknowledged substantial BitcoinOS contributions and continuing investment
SIP-0083 said Sovryn had contributed incubation, design, research, development, testing, communications, and community engagement throughout BitcoinOS development and committed further technical, audit, interface, marketing, infrastructure, and network-operation resources. Yago then called Sovryn a significant BitcoinOS participant.
The completed BOS launchpad sale recorded about $4.89 million in Origins' USD-valued amount-collected counter
Origins' two contiguous completed backend periods record 609,509,366.81050959 BOS in tokensSold and $4,888,380.29942801134947357397 in the USD-valued usdCollected field across accepted crypto assets. Public-chain reconstruction identifies non-overlapping stablecoin roots plus high-confidence Bitcoin and Cardano collection candidates. Stablecoin face value and transaction-date Kraken daily VWAP for 20.0153 BTC and 2,440,904.338471 ADA produce a $4,169,986.839549 scale benchmark, or 85.3% of the counter. This is not Origins order-time accounting or an audited net-proceeds figure; complete order, rate, refund, allocation, exchange, banking, and Fireblocks records remain required.
High-confidence Bitcoin and Cardano Origins candidates rotated collectors in synchronized batches
Seven Cardano consolidation batches and the Bitcoin collector-A consolidation occurred within 16–23 minutes on 12 May. On 13 May, the main Cardano and Bitcoin rollovers landed at successor collectors 5 minutes 15 seconds apart, and their residual transfers followed 6 minutes 48 seconds apart. Sale timing, unique-deposit topology, official BOS-recipient crossmatches on Cardano, and this independent timing fingerprint support common Origins infrastructure attribution; they do not identify a natural-person controller.
The candidate BOS Bitcoin collector deposited into the terminal later used by the Exchequer route
Eight deposits totaling 20.0975 BTC reached one exact terminal address. Conservation through the candidate collection pool establishes a 20.0111-BTC sale-window lower bound, or 20.0109 BTC after excluding both test transfers. The Origins or Fireblocks vault-to-address inventory is needed to make the candidate mapping first-party-confirmed.
Long-running Sovryn operations key 0x509201…AbD6 provisioned three later DD/BOS owner keys
The key first-funded 0x5C07…96C2, 0xe31c…67C6, and 0x59c4…ed0F with consecutive Ethereum nonces inside four minutes. The following day 8C used those addresses in the five-owner set for the official BOS token-owner and allocation Safes.
8C deployed the official BOS token-owner and allocation Safe family with one five-key control set
The token-owner Safe and the allocation Safes used the exact five owner addresses later installed on DD. Net initial allocation balances reconcile BitcoinOS's published 32% ecosystem and 35% founding-entity buckets.
The fully reconciled third Cardano sale collector funded the official BOS distributor
The collector sent 8,000 ADA through a relay that forwarded 7,998.83 ADA to the official BOS Cardano distributor. The same collector's exact root, fee, and outflow ledger reconciles to zero; the public chain establishes this use but not its internal accounting category or authorization.
The BOS token began live trading
Address 8C created the cross-chain DD shared wallets 15 days later, and Exchequer multisig asset movements began 36 days later. Obtain Sovryn/BitcoinOS allocation, proceeds, and related-party records for this period.
8C created the DD shared wallet on BNB Chain, requiring two of five owner approvals
The same address created a matching Ethereum shared wallet 63 seconds later with the same five owners and two-signature requirement.
8C created the matching DD shared wallet on Ethereum
The Ethereum and BNB Chain DD shared wallets had the same owner list and two-signature requirement, later received assets routed from the Exchequer multisig, and reused the exact five-owner set from the official BOS token-owner and allocation Safe family. The same two keys approved all 14 observed Ethereum DD executions.
Two reconstructed BOS sale collectors transferred stablecoins, WBTC, and ETH directly to 0x509201…AbD6
Collector 0x1160…f08C sent 204,104 USDT, 30,057 USDC, and 3.606 ETH. Middle collector FeD3 sent 2,798 USDT, 2,024 USDC, 0.001 WBTC, and 1.196 ETH in the same consolidation window. Their sale function is established by exact participant-deposit sweeps, linked gas infrastructure, official vesting-beneficiary matches, cutover timing, collector succession, and published stage-price corroboration. The recipient address already links B7, Sovryn's official Ethereum bridge, DD, and the official BOS Safe family.
0x509201 sent 200,000 USDT into a Gemini forwarding route that deposited the exact amount at Gemini 4
Before the BOS collector receipts, 0x509201 held only 49,536 USDT. With no material intervening USDT inflow, balance conservation establishes that at least 150,463.919739 of the 200,000-USDT Gemini deposit came from the designated collector lot. The bounded minimum entering first-hop routes that terminate at publicly labeled Gemini, Kraken, and Coinbase addresses is 183,441.682473; after route losses and relay prebalances, at least 183,433.939419 necessarily reached those labeled exchange endpoints.
The same BOS collector sent swept participant RBTC into Sovryn's Exchequer multisig
Eleven participant-specific Rootstock deposit addresses swept 0.0222 RBTC into 0x1160…f08C, and every identified payer matched a later Community Sale vesting beneficiary. The collector then sent 0.0222 RBTC, net of onward transaction gas, into Sovryn's 0x924f… Exchequer. This is a direct BOS-presale-proceeds route into Sovryn's treasury and requires intercompany source-and-use reconciliation.
The Exchequer multisig held about $3.20 million of gross on-chain assets
At Rootstock block 8,265,000, a realized-output method valued non-SOV holdings at about $2.663 million and 5.07 million SOV at about $536,947 using Sovryn's on-chain reference price. A separate same-time price check reached $3.250 million. These figures value gross assets before unidentified liabilities or off-chain accounts.
Twenty-seven material Exchequer multisig operations moved treasury assets
The non-double-counted ledger records 24 primary exits and three final BNB bridge executions. Three executions sent 23.1464 RBTC out of the Exchequer, worth an estimated $2,122,679.92 in total using the one-minute Coinbase BTC-USD candle close containing each execution. The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e approved all 27. Tyrone's official deployment record later names this same wallet as its sender. Only four of the eight historical Exchequer owner addresses approved any operation in this set.
All three Exchequer-derived Bitcoin releases reached the exact earlier BOS-candidate terminal
After Rootstock-to-Bitcoin bridge and Bitcoin fees, three releases delivered 23.1395 BTC into the exact address previously used by the high-confidence BOS Bitcoin candidate. OKLink labels the terminal Gemini, while BitInfoCharts labels a recurring downstream consolidator OKEx. The address reuse is exact; venue, credited customer, beneficial owner, purpose, trades, withdrawals, and fiat proceeds require private records.
Cardano sale infrastructure and mint-derived BOS funded a Minswap BOS/ADA liquidity position
The third Cardano collector sent 277,396.064793 ADA to a purpose-created controller. A mint-derived reserve sent 36,670,452 BOS to the same address. The controller placed 277,394.921276 ADA and 36,652,194.91 BOS into an order that increased the Minswap V2 pool reserves by 277,392.171276 ADA and 36,652,194.91 BOS. All 30,314,501,400,595 returned LP units remained in an unspent controller output at the research cutoff; the controller's human identity and authorization remain unresolved.
Treasury-linked DLLR was converted to ZUSD and redeemed through Zero against borrower collateral
Five Exchequer transfers sent 569,214 DLLR to conversion wallet 8C. That wallet made five matching DLLR-to-ZUSD calls and eleven successful Zero redeemCollateral calls before five follow-on transfers returned 6.2281 RBTC to the Exchequer. Zero redemptions reduce borrower debt but also remove the oracle-priced RBTC equivalent, forcing a reduction in Bitcoin collateral exposure at the redeemer's chosen time. Because 8C held commingled balances and the successful calls exceeded the identified treasury DLLR input, not every redeemed unit or returned satoshi can be assigned solely to the Exchequer funds.
Sovryn's official X account told readers to stake SOV for BTC and USD income
The post said, “Stake SOV right now to earn up to 21.37% APR BTC and USD.” The preserved official embed response and screenshot record the solicitation and its timestamp.
Wallets staked SOV and lengthened existing locks during the promotion-to-notice period
Fifteen addresses directly added 111,068 SOV in 24 transactions. Twenty addresses lengthened locks on 9,962,956 SOV in 27 transactions. Individual victim files can join these transactions to dated evidence of promotion exposure, purchase and staking decisions, and loss.
DD sent Exchequer-attributed funds through the exact BOS-linked Ethereum forwarding route
DD sent 100,000 USDT to the same e1d4 proxy used after BOS collector receipts; the proxy forwarded the exact amount to the publicly labeled Gemini 4 gateway. The January route's standalone Exchequer-origin lower bound is 66,645 USDT. Exchange records are required to identify the credited customer, trades, withdrawals, and beneficial owner.
Tyrone-authored code shut down principal fee claims on live Rootstock mainnet
The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e deployed the code and submitted the request to the Exchequer multisig, and enough Exchequer owners approved it. Tyrone's official deployment record names this wallet as its sender. The live shutdown lasted 44 hours 20 minutes and began before the larger 29 January BTC decline. Yago later cited the recent BTC decline when justifying the February change that stole staker fee rights.
Archived staking-page HTML records a Webflow Last Published timestamp
The preserved HTML begins with Webflow metadata dated after the January claim shutdown and before Yago's 17 February notice. Webflow revision, approval, and account logs should identify the exact page version and approvers behind that publication event.
Seven B7-funded wallets withdrew 10,048,901 SOV from staking
The withdrawals occurred in 1 hour 52 minutes 24 seconds. Four of those seven wallets then opened the February loans.
Four linked wallets opened SOV-backed RBTC loans within 15 minutes 12 seconds
The loans paid a total of 1.465 RBTC from the lender pool to the borrower wallets and added risk from selling illiquid SOV collateral in a liquidation.
Yago announced the RBTC and ZUSD payout pause and the revenue change this dossier identifies as theft
The announcement came 12 hours 35 minutes after the last linked loan opened. It said the change would follow the next payout; the Exchequer multisig still held the contract powers needed to carry it out.
The FeeSharing deployment/submission wallet at 0xfEE171…4a9e7e submitted the 100%-withholding change
A Tyrone-authored deployment commit identifies 0xfEE171…4a9e7e as the sender. That wallet deployed the replacement code and submitted the Exchequer multisig upgrade, RBTC withholding, and ZUSD withholding actions within 3 minutes 16 seconds.
The Exchequer multisig activated 100% withholding for RBTC and ZUSD
Enough Exchequer owners approved the replacement code, and the 0xfEE171…4a9e7e deployment wallet executed both token additions. Staker claim entries for these fees stopped before any Bitocracy vote.
Six linked wallets staked 6,986,587 SOV within 43 minutes 16 seconds
Three wallets that had not borrowed restaked their exact withdrawn amounts. Nearly all stakes used the same 16 February 2029 lock target.
Public Disclosure #2 warned that the linked loans threatened RBTC lenders
The notice identified all four loan transactions, asked Yago and Nahari to close the loans, and requested safer SOV-collateral rules.
B7-funded voting power defeated the SIP-0088 recovery proposals
Five B7-first-funded wallets cast all 62,572,733.758251524367271838 votes against the executable proposals to reverse the fee change and transfer FeeSharing control to Bitocracy.
Yago sponsored a proposal to ratify the already executed staking-revenue theft
SIP-0089 was expressly presented as approval and formalization after the operational decision and contract change had already occurred.
Yago acknowledged BOS-on-behalf-of-Sovryn payments and then denied fund mingling
At 35:03 on Community Call 73, Yago said BOS had paid some funds on Sovryn's behalf and that they needed year-end consolidation. At 44:42, asked whether Sovryn was mingling funds with BOS, he answered 'No.' The DD/BOS shared-control and payment record requires the intercompany ledger, payment mapping, invoices, approvals, and reconciliation supporting both statements.
DD funds passed through 0x509201 and a sibling forwarding proxy to the same Ethereum terminal
DD sent 120,000 USDT to 0x509201, which exchanged that amount through Curve for 119,923 USDC and then sent 122,000 USDC through sibling proxy f6c8 to the same 5f65 terminal, drawing on a pre-existing USDC balance for the difference. Allocating DD's maximum other funds only once across the January and March routes and deducting maximum March dilution establishes a joint 133,809.640217-unit Exchequer-origin lower bound at the terminal. Across all DD outflows, at least 411,750.640097 nominal stablecoin units reached either that terminal or recurring recipient wallets. These are gross-arrival lower bounds, not unique dollars or proof of purpose.
Borrower-cluster value reached the wallet that later funded a Sovryn USDt0 campaign
February borrower and later hub B493 sent 0.236 RBTC to campaign signer de169, a registered owner-address of the 0x924f Exchequer multisig, which remains the current guardian of both Governor contracts. De169 later sent the transaction identified in the transaction audit as an RBTC-to-USDt0 swap and signed the 14,417-USDt0 Merkl campaign transaction. Merkl's official opportunity page identifies Sovryn as the protocol, Rootstock as the chain, an approximately 14,000-USDt0 reward pool, and a Deposit link to Sovryn's market-making dapp. Obtain the swap receipt, full account ledger, campaign authorization, and signer records to complete the source-of-funds accounting.
Nine liquidation events struck three February loans
Liquidators repaid 0.3545 WRBTC and seized 1,571,209 SOV. All four February positions remained active and unsafe at the following audit snapshot.
The pinned lender-pool snapshot showed all 11 active SOV-backed loans unsafe
At Rootstock block 9,162,594, selling all SOV collateral through the on-chain exchange pool produced a modeled 4.0441-RBTC lender shortfall.
Sovryn's live staking page continued to advertise BTC rewards and SOV purchases
The official page displayed “up to 20% APR,” “Rewards in BTC,” “Payouts in BTC,” and a “Buy SOV” button months after the 100% RBTC and ZUSD withholding action. The page HTML, screenshots, capture time, and hashes are preserved.
Appendix B
Call evidence ledger
All nine excerpts were checked against the complete calls. Their captions, continuous time ranges, visual treatment, source links, and file fingerprints are recorded with each player.
Complete question and answer on the treasury reaction, BTC exposure, and replenishment
Complete question and answer describing overall treasury consolidation
Yago responds when the founding-member loan is raised
Excerpt checked against the full call
“No, of course not. What’s it got to do with me? Or the conversation that we’re having? Like, people who own SOV can do with it whatever they choose.”
Asked whether Sovryn was mingling funds with BOS, Yago answers no
Excerpt checked against the full call
“No.”
Complete question and answer containing the general third-party FastBTC explanation
Follow-up states the duty to protect RBTC lenders from illiquid collateral
Complete question and answer containing the inability to explain the precise redemption method
Complete question and answer containing the baseless, conspiratorial, and noise response
Complete question and answer containing the bad-faith, lack-of-understanding, and no-deep-mystery response
Appendix C
Primary records and exhibits
Public links let readers inspect each source and rerun the calculations. The evidence packet preserves the datasets and methods; restricted originals and private submissions remain outside the public site.
Exhibit index
- EX-01 Theft of Sovryn's usable treasury assetsOn-chain recordDossier conclusioncurated-transactions.json · asset-map.json · snapshots.json reproduced
- EX-02 Registered-owner-key Exchequer execution and leadership's organizational acknowledgmentOn-chain recordDirect source recordDossier conclusioncurated-transactions.json · case-chronology.json · call-excerpts.json registered-owner confirmations and leadership acknowledgment reproduced; custody and instruction records listed for allocation
- EX-03 RBTC route and distinct FastBTC flowOn-chain recordDirect source recordDossier conclusionRecords authorities should compelasset-map.json · btc-origins-flow.json · exchequer-shared-terminal-flow.json · verify-fund-flows.mjs · snapshots.json · call-excerpts.json · sources.json Exchequer RBTC path, exact Bitcoin terminal reuse, and Ethereum shared-terminal lower bounds reproduced; venue, customer, beneficial-owner, purpose, and liability records not public
- EX-04 Staking solicitation, retained FeeSharing authority, pre-vote staking-revenue theft, and investor damagesOn-chain recordDirect source recordDossier conclusionRecords authorities should compelcase-chronology.json · snapshots.json · fee-authority-records.json · visual-exhibits.json · sources.json official representations, code, transactions, price timing, and withheld-fee arithmetic reproduced
- EX-05 Notice, response, liquidation, and lender harmOn-chain recordDirect source recordDossier conclusionRecords authorities should compelcase-chronology.json · snapshots.json · loan-records.json · pool-model-inputs.json · call-excerpts.json pool and loss-model arithmetic reproduced; continuous media published
- EX-06 SIP-0085 outcome-determinative linked votes, SIP-0088 opposition, and SIP-0089 ratificationOn-chain recordDossier conclusionsnapshots.json · governance-attribution.json · sources.json funding paths, attributed balances, and vote arithmetic reproduced
- EX-07 Named-actor accountability and attribution recordsDirect source recordOn-chain recordDossier conclusionRecords authorities should compelactor-attribution.json · sources.json · fee-authority-records.json · asset-map.json documentary and operational attribution stated with limits
- EX-08 BitcoinOS sale claims, proceeds routes, public delivery status, and mathematically verified trust assumptionsDirect source recordOn-chain recordDossier conclusionRecords authorities should compelsources.json · bitcoinos-claim-records.json · bos-launchpad-sale.json · bos-presale-wallet-flows.json · bos-proceeds-509-trace.json · btc-origins-flow.json · cardano-origins-flow.json · exchequer-shared-terminal-flow.json · verify-fund-flows.mjs · bos-origins-home-2026-08-21.base64.txt · bos-origins-ledger-one-2026-08-21.json · bos-origins-ledger-two-2026-08-21.json · verify-bos-launchpad-sale.mjs · verify-bos-presale-wallet-flows.mjs · verify-bos-proceeds-509-trace.mjs · bitcoinos-excerpts.json · bitcoinos-trust-model.json · bitcoinos-trust-model.md · verify-bitcoinos-trust-model.mjs · bitcoinos-invalid-proof.patch · bitcoinos-invalid-proof.cfg · case-chronology.json dated claim matrix, preserved Origins counters, reconstructed EVM/BNB/Bitcoin/Cardano collection and use routes, exact shared terminals, source-neutral conservation bounds, cross-chain benchmark, pinned-code audit, consensus construction, exhaustive coalition counts, and reproducible invalid-proof counterexample; purchaser, exchange, controller, and internal records listed for completion
- EX-10 Asset tracing and media handoffOn-chain recordDirect source recordDossier conclusionRecords authorities should compelasset-map.json · media-brief.md · case-chronology.json publication media brief and asset-tracing handoff
- EX-11 Official marketing captures, supplied screenshots, and identity portraitsDirect source recordDossier conclusionRecords authorities should compelvisual-exhibits.json · actor-attribution.json · sources.json visual exhibits published with provenance and source credits
- EX-12 Common funding wallet B7: origin funding, address setup, and coordinated activityOn-chain recordDossier conclusionRecords authorities should compelb7-activity-coordination.json · governance-attribution.json · snapshots.json origin funding, setup callbacks, address metrics, February stake/loan/restake sequence, and exact legacy-loan handoff reproduced; key-custody and instruction records listed for allocation
- EX-13 Borrower-cluster value path to the Sovryn USDt0 incentive campaignOn-chain recordDirect source recordDossier conclusionRecords authorities should compelloan-value-tracing.json · loan-records.json · actor-attribution.json · visual-exhibits.json · sources.json selected transfers, the identified swap transaction, campaign outflows, official Merkl opportunity, and Sovryn dapp deposit link reproduced; swap receipt, account ledger, authorization, and custody records listed for completion
- EX-14 DD, BOS sale proceeds, and BitcoinOS shared custody, signer, deployment, and payment infrastructureOn-chain recordDirect source recordDossier conclusionRecords authorities should compeldd-bitcoinos-control.json · bos-presale-wallet-flows.json · verify-bos-presale-wallet-flows.mjs · bos-proceeds-509-trace.json · verify-bos-proceeds-509-trace.mjs · btc-origins-flow.json · cardano-origins-flow.json · exchequer-shared-terminal-flow.json · verify-fund-flows.mjs · asset-map.json · case-chronology.json · bitcoinos-claim-records.json · sources.json cross-chain Safe deployments, exact owner-set overlap, execution quorums, BOS allocations, reconstructed EVM/BNB/Bitcoin/Cardano collection routes, 0x509201 exchange routes, exact Bitcoin and Ethereum terminal reuse, Exchequer deposits, Cardano distributor/liquidity uses, B7 and Sovryn bridge links, DD payments, and statement chronology reproduced; exchange, beneficial-controller, and intercompany accounting records listed for completion
Public source index
- 2026-03-08 Public Disclosure #1 — Exchequer RBTC to exchange-style cluster (opens in a new tab) originating investigation
- 2026-03-08 Public Disclosure #2 — Founding-member SOV collateral loan (opens in a new tab) originating investigation
- 2026-03-28 Public Disclosure #3 — Exchequer total assets withdrawn (opens in a new tab) originating investigation
- 2026-08-18 Public Disclosure #4 — SOV loans liquidate, bad debt, and profit trail (opens in a new tab) originating investigation
- 2026-02-17 Staking update: temporary adjustment to staking rewards (opens in a new tab) direct statement
- 2024-12-08 BOS token and the premium future of Sovryn (opens in a new tab) direct statement on SOV yield and staking desirability
- 2023-02-22 Mo' money, less problems (opens in a new tab) direct statement on protocol revenue and SOV-staker yield
- 2026-02-17 Yago statement that staking should remain compelling and distributions should come from real revenue (opens in a new tab) direct statement on staking materiality
- 2026-03-23 Ratification of temporary revenue redirection to Exchequer (opens in a new tab) direct statement
- 2020-12-15 DeFi on Bitcoin gets a boost as Sovryn launches on RSK (opens in a new tab) official leadership record
- 2020-12-16 Greenfield leads Sovryn funding round (opens in a new tab) contemporaneous founder record
- Undated SIP-0015 — Sovryn Treasury Management (opens in a new tab) governance record
- 2021-04-27 Sovryn Exchequer Committee meeting summary — 27 April 2021 (opens in a new tab) executive treasury record
- Undated SIP-0041 — Role assignments and wallets (opens in a new tab) governance record
- Undated SIP-0046 Part 1 — Contract ownership transition (opens in a new tab) governance record
- Undated SIP-0047 — Bitocracy Guardian (opens in a new tab) governance record
- 2024-12-06 SIP-0085 — BOS token distribution within Sovryn (opens in a new tab) governance record
- 2022-03-27 SIP-0043 is live — critical governance bug fix (opens in a new tab) governance rule record
- 2026-03 SIP-0088 — Emergency revert FeeSharing changes and transfer ownership to Bitocracy (opens in a new tab) governance record
- 2026-03-08 Yago response on intended FeeSharing contract control (opens in a new tab) direct statement
- 2026-02-25 FeeSharing 100% withholding implementation merge (opens in a new tab) code record
- 2026-02-19 FeeSharing token-withholding implementation pull request (opens in a new tab) code and implementation record
- 2026-02-19 FeeSharing deployment artifact (opens in a new tab) code record
- 2026-01-28 Temporary FeeSharing claim-shutdown commit (opens in a new tab) code and implementation record
- 2026-01-12 Stake SOV right now to earn up to 21.37% APR BTC and USD (opens in a new tab) official investor solicitation
- 2026-01-12 Official X oEmbed record for Sovryn staking promotion (opens in a new tab) official platform record
- Undated Sovryn Staking contract on Rootstock (opens in a new tab) on-chain contract record
- Undated Official Sovryn staking event definitions at immutable commit (opens in a new tab) technical primary record
- Undated Sovryn official channels directory (opens in a new tab) official account record
- Undated Stake SOV to earn BTC (opens in a new tab) official product representation
- 2026-08-20 capture Sovryn staking — rewards and payouts in BTC (opens in a new tab) official current investor solicitation
- Undated Earn with Sovryn — staking revenue description (opens in a new tab) official product representation
- 2024-09-11 Stake SOV to Earn Bitcoin (opens in a new tab) official product representation
- 2026-01-28 BTC-USD five-minute candles — January 28, 2026 (opens in a new tab) primary market data
- 2026 BTC-USD daily candles — January and February 2026 (opens in a new tab) primary market data
- 2025-12-01 BTC-USD five-minute candle at the 1 December Exchequer snapshot (opens in a new tab) primary market data
- 2025-12-04 BTC-USD one-minute candle containing the 4 December Exchequer RBTC execution (opens in a new tab) primary market data
- 2026-01-22 BTC-USD one-minute candle containing the 22 January Exchequer RBTC execution (opens in a new tab) primary market data
- 2026-01-24 BTC-USD one-minute candle containing the 24 January Exchequer RBTC execution (opens in a new tab) primary market data
- 2025-12-01 ETH-USD five-minute candle at the 1 December Exchequer snapshot (opens in a new tab) primary market data
- 2025-12-01 BNB-USDT five-minute candle at the 1 December Exchequer snapshot (opens in a new tab) primary market data
- 2021 The journey of Sovryn mutant Franklin Richards (opens in a new tab) official technical-lead identity record
- Undated Sovryn Community Call #72 (opens in a new tab) direct statement
- Undated Sovryn Community Call #73 (opens in a new tab) direct statement
- Undated Bitocracy 3.0 and Bitcoin 2.0 (opens in a new tab) direct statement
- Undated Sovryn raises $5.4 million; user-ownership representations (opens in a new tab) organizational statement
- 2026-03-19 Sovryn Financial Report Q4 2024–Q4 2025 (opens in a new tab) management report
- 2021-04-14 DeFi Technologies announces co-investment into Sovryn (opens in a new tab) official contributor identity record
- Undated Fee Sharing documentation (opens in a new tab) technical documentation
- Undated Zero rewards documentation (opens in a new tab) technical documentation
- 2024-09-25 BitcoinOS open-sources BitSNARK v0.1 (opens in a new tab) technical and organizational primary record
- 2024-10-06 BitSNARK v0.1 README at immutable public-mainline commit (opens in a new tab) technical primary record
- 2025-02-28 BitSNARK public README at immutable v0.2 commit (opens in a new tab) technical primary record
- 2025-02-26 BitSNARK repository snapshot with 26 February 2025 Git metadata (opens in a new tab) immutable code snapshot
- 2025-02-28 BitSNARK v0.2 pinned public tree and executed build/test record (opens in a new tab) immutable code and reproducible execution record
- 2025-02-28 BitSNARK Multiplier(1000) Circom test circuit at immutable commit (opens in a new tab) code primary record
- 2025-02-28 BitSNARK hard-coded Groth16 proof and verification-key path at immutable commit (opens in a new tab) code primary record
- 2025-02-28 BitSNARK verifier-response and timeout paths at immutable commit (opens in a new tab) code primary record
- 2025-02-28 BitSNARK intended two-key locked-funds leaf and pre-signing setup at immutable commit (opens in a new tab) code primary record
- 2025-02-28 BitSNARK TLA+ transition model at immutable commit (opens in a new tab) formal-model primary record
- 2025-02-28 BitSNARK locked-funds leaf and timeout transaction templates at immutable commit (opens in a new tab) code primary record
- Undated BitSNARK decoder verification test at immutable commit (opens in a new tab) technical primary record
- Undated BIP141 — Segregated Witness consensus specification (opens in a new tab) Bitcoin consensus primary record
- Undated BIP143 — version-0 witness signature digest (opens in a new tab) Bitcoin consensus primary record
- Undated BIP341 — Taproot consensus rules and signature message (opens in a new tab) Bitcoin consensus primary record
- Undated BIP342 — Validation of Taproot Scripts (opens in a new tab) Bitcoin consensus primary record
- 2026-07-07 Bitcoin Core 31.1 release binaries and hashes (opens in a new tab) consensus implementation release record
- 2025-06 BitSNARK and Grail technical white paper (opens in a new tab) technical primary record
- Undated BitcoinOS technology page (opens in a new tab) organizational statement
- Undated BitcoinOS technical documentation (opens in a new tab) technical primary record
- 2024-01-24 BitcoinOS: Building in Layers to Unlock Bitcoin's Potential (opens in a new tab) Yago-authored organizational statement
- 2024-08-07 How We Did It: The First ZK Proof on Bitcoin — Edan Yago & Gadi Guy at Bitcoin Nashville (opens in a new tab) official video; direct Edan Yago statement
- 2025-01-29 Bitcoin Learns New Tricks: Your Portfolio's Next Move | Swiss Web3 Fest Keynote w/ Edan Yago (opens in a new tab) official video; direct Edan Yago statement
- 2025-01 Manifesto: Bringing Crypto Home To Bitcoin (opens in a new tab) organizational statement with technical qualification
- 2025-02-19 BitcoinOS Launches “Holy Grail” Bitcoin Bridge App Ahead of $BOS Presale (opens in a new tab) paid promotional article with attributed Edan Yago statement
- 2025-06-12 BitcoinOS Live! Interview with Yago | Cardano, ZK-proofs, and $BOS token pre-sale (opens in a new tab) third-party presale interview; direct Edan Yago statement
- 2025-02-16 Grail testnet bridge launch record (opens in a new tab) technical primary record
- 2025-02-27 BOS presale: Be Early to Bitcoin Again (opens in a new tab) fundraising and investor-marketing primary record
- 2025-03-20 BOS open-sources BitSNARK v0.2 (opens in a new tab) technical and organizational primary record
- 2025-04-14 Revolutionizing Bitcoin: An Exclusive Interview with Gadi Ghai, CTO of BitcoinOS (opens in a new tab) third-party interview; direct Gadi Guy statement
- 2025-04-24 BOS Token Presale Phase 2 Coming Soon — Be Early to Bitcoin Again (opens in a new tab) fundraising result and promotional primary record
- 2025-05-08 BOS Presale Phase 2 is Live (opens in a new tab) fundraising continuation primary record
- 2025-07-03 BOS Presale Maintenance Notice (opens in a new tab) fundraising migration primary record
- 2026-08-21 Origins project and backend-period index (opens in a new tab) first-party launchpad metadata retrieved at research cutoff
- 2026-08-21 Origins BOS completed backend period 3bee1d18 (opens in a new tab) first-party completed launchpad counter retrieved at research cutoff
- 2026-08-21 Origins BOS completed backend period 982bd8f6 (opens in a new tab) first-party completed launchpad counter retrieved at research cutoff
- Undated Grail Pro system architecture (opens in a new tab) technical primary record
- Undated Grail Pro technical overview (opens in a new tab) technical primary record
- Undated Grail Pro institutional integration (opens in a new tab) technical primary record
- Undated Grail Pro frontend trust model (opens in a new tab) technical primary record
- Undated Grail Pro operator deployment instructions (opens in a new tab) technical primary record
- Undated Grail Pro BTC-to-zkBTC bridging workflow (opens in a new tab) technical primary record
- 2025-09 Grail Pro: Bringing Institutional Bitcoin to DeFi (opens in a new tab) organizational and technical primary record
- 2025-03-03 BOS presale opening announcement (opens in a new tab) fundraising primary record
- 2025-10-20 BOS presale closing notice (opens in a new tab) fundraising primary record
- 2025-10-29 BOS TGE and trading announcement (opens in a new tab) fundraising primary record
- 2025-08 zkBTC institutional pilot announcement (opens in a new tab) organizational statement
- 2024-11-28 Philip DiSarro and Edan Yago bridge-trust exchange transcript (opens in a new tab) third-party transcript requiring audio preservation
- 2025-09-18 BTC OS Limited MiCA white paper (opens in a new tab) regulatory filing
- 2024-07-23 Reported final BitSNARK demonstration transaction (opens in a new tab) on-chain record
- 2024-07-31 Bitcoin rollups are closer than you think (opens in a new tab) technical reporting
- 2025-03-20 Bitcoin DeFi expansion faces fork dilemma (opens in a new tab) attributed interview
- Undated BitcoinOS team and leadership profiles (opens in a new tab) official identity source
- Undated Grail bridge frontend terms and conditions at pinned source commit (opens in a new tab) public frontend source and service terms
- Undated Edan Yago speaker profile (opens in a new tab) official event identity and portrait source
- 2025 Elan Nahari — Real-World Asset Summit 2025 (opens in a new tab) official event identity and portrait source
- Undated Weikeng Chen research and publication record (opens in a new tab) researcher profile
- 2024-07-24 exchange BitVM Builders Telegram group (opens in a new tab) public Telegram group containing the displayed Yago–Chen exchange
- 2024-07-24 Yago says BitcoinOS completed the mainnet demonstration (opens in a new tab) native public Telegram message
- 2024-07-24 Weikeng Chen challenges the covenant-without-OP_CAT claim (opens in a new tab) native public Telegram message
- 2024-07-24 Weikeng Chen warns Yago about the technical team's claims (opens in a new tab) native public Telegram message
- 2024-07-24 Super Testnet explains n-of-n covenant emulation and declines to vouch for BitcoinOS (opens in a new tab) native public Telegram thread
- 2024-07-24 Kevin He identifies trust assumptions and open implementation questions (opens in a new tab) native public Telegram thread
- Undated BitVM2 and bridge technical overview (opens in a new tab) technical primary record
- Undated BitVM Bridge: A Trust-Minimized Bitcoin Bridge (opens in a new tab) technical paper
- 2020-06-30 Bitcoin Covenants: Three Ways to Control the Future (opens in a new tab) technical paper
- 2026-07-13 Supply RBTC/USDT0 Liquidity (opens in a new tab) official campaign and Sovryn deposit-link record
- Undated Create a Merkl incentive campaign (opens in a new tab) technical primary record
- 2024-06-18 Yago states that Sovryn had not funded BitcoinOS and describes separate contributors and funding (opens in a new tab) direct funding and organizational statement
- 2024-06-18 Yago states that BOS funds would not come from Sovryn's treasury (opens in a new tab) direct treasury-funding statement
- 2024-06-20 Sovryn Community Call 63 — BitcoinOS funding and contributor separation statement (opens in a new tab) direct video statement
- 2024-07-02 BitcoinOS Q&A for discussion (opens in a new tab) direct statement and organizational planning record
- 2024-11-04 SIP-0083 — Sovryn as BitcoinOS contributor and BOS token launch participant (opens in a new tab) official governance and resource-allocation record
- 2024-11-07 Sovryn Community Call 66 — Sovryn described as a significant BitcoinOS participant (opens in a new tab) direct video statement
- 2026-03-27 Yago says BOS paid funds on Sovryn's behalf before year-end consolidation (opens in a new tab) direct cross-project payment statement
- 2026-03-27 Yago answers a question about Sovryn and BOS fund mingling (opens in a new tab) direct cross-project accounting statement
- 2026-08-22 retrieval DD Ethereum Safe state and owner set (opens in a new tab) on-chain indexed Safe state
- 2026-08-22 retrieval DD BNB Chain Safe state and owner set (opens in a new tab) on-chain indexed Safe state
- 2025-11-13 DD Ethereum Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-11-13 DD BNB Chain Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2026-08-22 retrieval DD Ethereum Safe multisignature transaction record (opens in a new tab) on-chain indexed execution and confirmation record
- 2026-08-22 retrieval Official BOS token address and allocation schedule (opens in a new tab) official token and allocation record
- 2026-08-22 retrieval Ethereum BOS token-owner Safe state (opens in a new tab) on-chain indexed token-administration Safe state
- 2025-10-23 Ethereum BOS token-owner Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-10-23 Inferred BOS ecosystem-allocation Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-10-23 Inferred BOS founding-allocation Safe 50db creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-10-23 Inferred BOS founding-allocation Safe 56a creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2025-10-23 Inferred BOS founding-allocation Safe 06D creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2026-08-22 retrieval BOS transfer ledger for the inferred ecosystem-allocation Safe (opens in a new tab) on-chain BOS transfer ledger
- 2026-08-22 retrieval BOS transfer ledger for inferred founding-allocation Safe 50db (opens in a new tab) on-chain BOS transfer ledger
- 2026-08-22 retrieval BOS transfer ledger for inferred founding-allocation Safe 56a (opens in a new tab) on-chain BOS transfer ledger
- 2026-08-22 retrieval BOS transfer ledger for inferred founding-allocation Safe 06D (opens in a new tab) on-chain BOS transfer ledger
- 2025-10-28 BOS administration Safe allocation transaction (opens in a new tab) on-chain token-allocation record
- Undated Sovryn Ethereum–Rootstock bridge mainnet configuration (opens in a new tab) official code and contract registry
- 2020-12-17 B7 funds the later DD/BOS operating key 0x509201…AbD6 (opens in a new tab) on-chain funding transaction
- 2025-10-22 0x509201…AbD6 first-funds the shared DD/BOS owner key 0x5C07…96C2 (opens in a new tab) on-chain owner-key provisioning transaction
- 2025-10-22 0x509201…AbD6 first-funds shared DD/BOS owner address e31c (opens in a new tab) on-chain owner-address provisioning transaction
- 2025-10-22 0x509201…AbD6 first-funds shared DD/BOS owner address 59c4 (opens in a new tab) on-chain owner-address provisioning transaction
- 2026-08-22 retrieval Earlier recurring-payment Safe solely controlled by 0x509201…AbD6 (opens in a new tab) on-chain indexed Safe state and payment history
- 2021-10-05 Earlier recurring-payment Safe creation record (opens in a new tab) on-chain indexed Safe deployment record
- 2026-08-22 retrieval DD BNB Chain multisignature transaction record (opens in a new tab) on-chain indexed execution and confirmation record
- 2025-12-01 DD sends 70 ETH to owner and approver 0x509201…AbD6 (opens in a new tab) on-chain direct payment and Safe execution
- 2026-03-30 DD sends 120,000 USDT to owner and approver 0x509201…AbD6 (opens in a new tab) on-chain direct payment and Safe execution
- 2026-08-22 state observation Official Ethereum BOS token proxy and owner read (opens in a new tab) on-chain contract state
- 2021-12-04/2022-11-04 0x509201…AbD6 USDT transfers to Sovryn's official Ethereum bridge (opens in a new tab) on-chain token-transfer history
- 2026-08-22 retrieval Earlier 0x509201…AbD6 payment-Safe execution history (opens in a new tab) on-chain indexed payment execution record
- 2025-06-19 Sovryn Origins multichain launchpad and unique-deposit-address model (opens in a new tab) first-party sale-infrastructure description
- 2025-03-03/2025-07-30 Early BOS Origins Ethereum collector BB55 (opens in a new tab) on-chain collector address record
- 2025-05-13/2026-04-27 Middle BOS Origins Ethereum collector FeD3 (opens in a new tab) on-chain collector address record
- 2025-07-10/2025-11-14 Post-maintenance BOS Origins collector 1160 (opens in a new tab) on-chain collector address record
- 2025-05-12 Early BOS deposit-gas wallet funds the later multichain deposit-gas wallet (opens in a new tab) on-chain sale-infrastructure continuity transaction
- 2025-05-13 Early BOS deposit-gas wallet funds the middle collector's deposit-gas wallet (opens in a new tab) on-chain sale-infrastructure continuity transaction
- 2025-07-09 Middle BOS deposit-gas wallet funds the later multichain deposit-gas wallet (opens in a new tab) on-chain sale-infrastructure continuity transaction
- 2025-05-09 Representative 6,000-USDT BOS buyer-to-deposit-to-collector trace (opens in a new tab) on-chain participant payment and collection trace
- 2025-05-21 Representative 100-DAI BOS buyer-to-deposit-to-collector trace (opens in a new tab) on-chain participant payment and collection trace
- 2025-08-15 Representative 50-USDC post-maintenance BOS buyer-to-deposit-to-collector trace (opens in a new tab) on-chain participant payment and collection trace
- 2025-05-13 Early BOS collector transfers USDC to the middle collector (opens in a new tab) on-chain collector-succession transaction
- 2025-05-13 Early BOS collector transfers USDT to the middle collector (opens in a new tab) on-chain collector-succession transaction
- 2025-03-05/2025-03-17 Early BOS collector relay route to Binance 14 (opens in a new tab) on-chain collector and exchange-deposit route
- 2025-05-21 Middle BOS collector transfers pooled stablecoins to operations wallet 4ad662 (opens in a new tab) on-chain collector destination route
- 2025-11-14/2026-04-27 Middle BOS collector transfers canonical assets directly to 0x509201 (opens in a new tab) on-chain collector destination route
- 2025-07-29 Later BOS collectors reuse the early Binance relay (opens in a new tab) on-chain collector destination continuity route
- 2024-09-09 0x509201 first-funds operations wallet 4ad662 (opens in a new tab) on-chain address-funding transaction
- 2025-06-03 Operations wallet 4ad662 transfers canonical stablecoins to 0x509201 (opens in a new tab) on-chain operational transfer record
- 2025-11-14 Post-maintenance BOS collector sends 204,103.50752 USDT to 0x509201 (opens in a new tab) on-chain collector destination transaction
- 2025-11-14 Post-maintenance BOS collector sends 30,056.588245 USDC to 0x509201 (opens in a new tab) on-chain collector destination transaction
- 2025-11-14 Post-maintenance BOS collector sends 3.605528140408725578 ETH to 0x509201 (opens in a new tab) on-chain collector destination transaction
- 2025-11-26 Post-maintenance BOS collector sends swept RBTC into Sovryn's Exchequer (opens in a new tab) on-chain BOS proceeds and Sovryn treasury route
- 2025-10/2026-08 retrieval BOS Community Sale vesting claim page (opens in a new tab) first-party distribution and claim record
- 2025-10-23/2026-08-22 Official Origins BOS Community Sale vesting vault (opens in a new tab) verified on-chain vesting contract and first-party registry record
- 2025-10-23 BOS Community Sale vesting vault creation transaction (opens in a new tab) on-chain deployment record
- 2026-03-17 Emergency cancellation of two BOS Community Sale schedules (opens in a new tab) on-chain vesting cancellation and recovery record
- Undated BOS collector 1160 participant deposits and onward sweep on Arbitrum (opens in a new tab) on-chain multichain sale-infrastructure record
- Undated BOS collector 1160 participant deposits on Polygon (opens in a new tab) on-chain multichain sale-infrastructure record
- 2026-08-22 retrieval 0x509201 Ethereum canonical-token source-and-use ledger (opens in a new tab) on-chain account and canonical-token history
- 2025-11-20/2025-11-25 0x509201 sends 200,000 USDT through a recurring Gemini-labeled deposit route (opens in a new tab) on-chain exchange-deposit route
- 2026-08-22 retrieval Gemini 4 exchange gateway address (opens in a new tab) public exchange-address attribution
- 2025-11-18/2025-11-21 0x509201 stablecoin routes to Kraken Hot Wallet 4 (opens in a new tab) on-chain exchange-deposit routes
- 2025-11-18/2025-11-30 0x509201 USDC routes to Coinbase 10 (opens in a new tab) on-chain exchange-deposit routes and official address metadata
- 2025-11-21 0x509201 USDC route to the official Orbiter Ethereum maker (opens in a new tab) on-chain bridge-maker route
- 2025-11-14 BOS collectors transfer canonical BNB-chain stablecoins to 0x509201 (opens in a new tab) on-chain cross-chain collector consolidation
- 2026-08-22 state observation 0x509201 BNB-chain canonical stablecoin balances and transfer histories (opens in a new tab) on-chain account state and complete canonical-token history
- 2025-05-21/2025-07-29 FeD3 BNB-chain stablecoin route through 6C250D to Binance (opens in a new tab) on-chain collector and exchange-deposit route
- 2025-05-12/2025-11-14 Cross-chain 60c Origins collector branch and cleanup into 0x509201 (opens in a new tab) on-chain participant, vesting, and cross-chain collector trace
- 2026-08-22 retrieval Manage deposits at scale (opens in a new tab) official custody architecture documentation
- 2025-03-03/2025-10-23 High-confidence BOS Origins Bitcoin collection candidate (opens in a new tab) on-chain candidate collection and rollover topology
- 2025-08-27/2025-10-23 Candidate BOS Bitcoin collector deposits into the later Exchequer terminal (opens in a new tab) on-chain common-terminal route
- 2026-08-22 retrieval Conflicting public labels around the common Bitcoin terminal (opens in a new tab) public exchange-infrastructure attribution
- 2026-08-22 retrieval Gemini crypto deposit-address workflow (opens in a new tab) official exchange deposit documentation
- 2025-12-04/2026-01-27 Three Exchequer RBTC routes reach the exact candidate-BOS Bitcoin terminal (opens in a new tab) on-chain cross-chain treasury route
- 2025-03-03/2025-07-09 Kraken XBT/USD daily OHLC benchmark for recovered BOS Bitcoin inputs (opens in a new tab) public market-price benchmark
- 2025-03-03/2025-10-22 Three high-confidence BOS Origins Cardano collector generations (opens in a new tab) on-chain candidate collection and rollover topology
- 2025-03-03/2025-08-27 Cardano BOS collectors use one relay to a Binance-labeled terminal (opens in a new tab) on-chain pooled collector and exchange route
- 2025-10-23 Post-cutover Cardano collector funds the official BOS distributor (opens in a new tab) on-chain sale-infrastructure use
- 2025-10-29/2026-08-22 Post-cutover Cardano proceeds and mint-derived BOS fund a Minswap liquidity position (opens in a new tab) on-chain sale-proceeds and liquidity route
- 2025-03-03/2025-10-22 Kraken ADA/USD daily OHLC benchmark for recovered BOS Cardano inputs (opens in a new tab) public market-price benchmark
- 2025-12-04/2026-01-20 Exchequer-origin routes reconcile to 508,947.877906 canonical USDT at DD (opens in a new tab) on-chain cross-chain source reconciliation
- 2026-01-12/2026-03-30 Exchequer-attributed DD funds reuse the BOS-linked Ethereum forwarding route (opens in a new tab) on-chain common-terminal and conservation record
- 2025-03-03/2025-10-22 Non-overlapping BOS Origins BNB Chain stablecoin roots (opens in a new tab) on-chain candidate collection topology and canonical-token ledger
Release checklist
Publication record
The public release was published only after the narrative, media, captions, hashes, redactions, evidence packet, and recovery materials passed the recorded release checklist.

