Victim-led investigation · Evidence dossier 01

The Sovryn Treasury Theft

This dossier concludes that Sovryn’s usable treasury and stakers’ promised fee revenue were stolen through an insider-directed course, while linked borrowing shifted losses onto RBTC lenders.

23.1464RBTC—approximately $2.12 million at the three transfer times—stolen from Sovryn’s Exchequer multisig through the Rootstock-to-Bitcoin transit wallet (D9)
0.2912 RBTC
+ 12,215 ZUSD
removed from stakers’ claim accounting by the measured snapshot after Sovryn promoted BTC income
27material Exchequer operations; the FeeSharing deployment wallet named in Tyrone’s official record approved every one
4.0441RBTC estimated lender-pool shortfall if all SOV loan collateral were sold through the only identified SOV/WRBTC exchange pool at once

SOV holders locked capital after being promised Bitcoin income. RBTC lenders supplied Bitcoin to Sovryn’s lending pool. The record shows treasury reserves leaving, staker fee rights being taken, linked borrowers extracting RBTC, recovery being blocked, and the same financial network handling BOS sale proceeds. Real investors were left with the losses and continuing exposure.

Who was harmed

Four groups carried the economic consequences while leadership retained the information and authority needed to explain, stop, or reverse the disputed conduct.

SOV stakers
Promised BTC and stablecoin fee revenue was removed from claim accounting after users had bought, locked, or extended SOV positions.
RBTC lenders
Linked borrowers extracted Bitcoin against thin SOV collateral, leaving a modeled 4.0441-RBTC pool shortfall and later liquidations.
Zero borrowers
Redemptions forced borrowers to surrender Bitcoin collateral at timing chosen by the redeemer, taking away the BTC exposure they used Zero to preserve.
Sovryn stakeholders
Usable treasury assets—including 23.1464 RBTC worth about $2.12 million when transferred—left the Exchequer and remain unreconciled in a complete public ledger.

The case in seven steps

A coordinated wallet network concentrated control. Treasury assets then moved through repeated multisig approvals, staker fee rights were taken, and linked borrowers drew Bitcoin from the lending pool. Users warned leadership, recovery was blocked, and Sovryn assets later appeared in the same financial network used by BOS sale proceeds.

Terms used in this dossierOpen the wallet, asset, and governance glossary
RBTC, WRBTC, and iWRBTC
RBTC is Bitcoin represented on Rootstock. WRBTC is its contract-compatible form. iWRBTC is Sovryn’s RBTC lending-pool contract and receipt token.
SOV stakers
Users locked SOV for voting power and protocol-fee revenue. Longer locks can carry more voting weight.
Address or wallet
A blockchain account identified by a public address. The address shows transactions; a signing key controls what it can send.
Exchequer multisig
Sovryn’s shared treasury wallet. A multisig requires a minimum number of registered owners to approve a transaction; three approvals were required during the treasury transfers studied here.
Bitocracy and SIP
Bitocracy is Sovryn’s SOV-weighted proposal and voting system. A SIP is a Sovryn Improvement Proposal submitted to that system.
FeeSharingCollector
The contract that recorded and distributed protocol fees to SOV stakers. Its replaceable code and administrative controls are central to this case.
ZUSD and USDt0
Dollar-linked stablecoins used in the fee and incentive-program records.
Governor and Guardian
Sovryn’s Governor contracts process governance proposals. A Guardian shared wallet holds emergency administrative powers over them.
B7 cluster
A defined group of 70 addresses linked by first-funding paths to B7. Their repeated synchronized actions establish one centrally directed operation.
Recurring wallet labels
B7 is the common funding wallet; D9 is the Rootstock-to-Bitcoin transit wallet; 8C is the Tyrone-linked conversion, routing, and Safe-deployment wallet; DD names matching 2-of-5 destination and payment Safes on Ethereum and BNB Chain whose five-owner set is also used across the official BOS token-control network; and 0xfEE171…4a9e7e is the FeeSharing deployment and Exchequer-submission wallet named in Tyrone’s official deployment record.
Exchange pool
A reserve pool—also called an automated market maker, or AMM—that sets a token’s sale price. A large sale receives progressively less as it drains the available Bitcoin.
  1. One coordinated setup became many wallets

    A shared wallet requiring two of three owners funded common funding wallet B7 · 0xb7d16f…ed81d8 , which then paid the first transaction fees for scores of addresses. Ten previously unused core wallets sent their first outgoing transaction straight back to B7 within minutes. On a holder list they look separate; their two-way setup and later synchronized activity establish a centrally directed operation.

    See the seed and wallet proof
  2. The linked lending risk began years earlier

    The B7-linked 2022 borrower wallet 8D51 opened a SOV-backed RBTC loan. It later received the same approximately 385,915 SOV that the February borrower wallet 4f39 sent, then put the full amount into three loans within 4m57s. The packet preserves the exact matching values. The surviving loan, identified as 0x839c…, now accounts for most of the cluster’s estimated shortfall.

    Inspect the legacy loan
  3. BOS sale receipts entered a shared operations network

    Origins recorded a $4.89 million USD-valued sale counter. Public-chain reconstruction now represents about $4.17 million at a matched daily-market benchmark, including high-confidence Bitcoin and Cardano collector pools. BOS receipts entered 0x509201, Sovryn’s Exchequer, and exchange routes later reused by Exchequer-derived funds.

    Follow the cross-project fund paths
  4. Usable treasury assets were stolen into the same financial network

    Twenty-seven material operations were used to steal RBTC and other reserves through a small set of routes. Every operation received the required approvals from at least three registered owners of the Exchequer multisig. Later tracing shows exact Bitcoin and Ethereum exchange infrastructure reused across BOS sale and Exchequer-derived routes.

    Follow the treasury exits
  5. Stake moved, four loans opened, staker revenue was stolen

    Seven B7-first-funded wallets withdrew approximately 10.05 million SOV from matured stakes in 1h52m24s. Four of them then opened loans inside 15m12s, supplying approximately 7.01 million SOV in the borrow calls for 1.465 RBTC in net payouts. Yago’s reward-pause announcement of the change documented here as theft followed the last opening by 12h35m, placing the loan session and policy change in one tightly ordered sequence.

    See the synchronized sequence
  6. Users warned leadership; the positions stayed open

    The transactions and lender risk were published. On Call #73, Yago said, “What’s it got to do with me?” He later called the loan link baseless and characterized the broader exchange as “conspiratorial thinking” and “noise.” The located public record contains no commitment to require repayment, pause affected lending, pursue any available protective action, or investigate the positions; linked voting defeated the executable recovery.

    Hear the response and inspect the loans
  7. Value reconverged; lenders remained exposed

    Borrower balances came back together, and cluster value reached USDt0 campaign signer de169 · 0xde1690…5f6af2 current registered owner-address of Sovryn’s 0x924f Exchequer multisig, which also guards both Governor contracts . That wallet later funded a USDt0 incentive campaign. August liquidations followed. At the 18 August measurement point, all five material cluster-linked positions remained active and below Sovryn’s required collateral level.

    Follow the campaign-funding path
The responsibility chain: The transaction history establishes a centrally directed B7-funded operation. Public records place Yago, Nahari, and Tyrone in the leadership, accounting, and implementation chain surrounding the same conduct. Yago set and announced policy, explained the treasury transfers documented here as theft, dismissed the lender warning, and sponsored ratification; custody and instruction records can allocate each operational key.

Search the evidence

Search by person, wallet, asset, proposal, or transaction. Every result returns to its original context and source record.

How findings are labeled and reproduced

We reconstructed transactions and contract balances directly from the named blockchains. Every current balance is tied to one stated block and time; this is a “pinned snapshot.” The public packet identifies any outside index used to find older or cross-chain records and provides the inputs needed to rerun each calculation.

On-chain record Direct source record Dossier conclusion Records authorities should compel
On-chain record
A transaction or contract state stored on a blockchain.
Direct source record
A dated post, document, code artifact, image, or recorded statement attributable to its source.
Dossier conclusion
The finding drawn from the records identified beside it.
Records authorities should compel
Private evidence that should be preserved and obtained through lawful process.

“Dossier conclusion” identifies this publication’s evidence-based finding. The record supports a referral for suspected fraud, misappropriation, and related offenses. Courts and authorities determine charges and liability after compulsory process.

Reader-facing precision: token amounts and percentages are rounded to economically meaningful precision so the story remains legible. Search fields, linked explorers, source JSON, and the downloadable evidence packet preserve the exact underlying values.

Four public notices that put leadership on notice

These disclosures establish what leadership was told and when. The underlying transactions, contract states, and calculations supply the technical proof below.

Pinned records control every published figure. The dossier uses the block snapshots, transaction records, measurement definitions, and tracing methods in the downloadable public packet.

Part I · Control and treasury theft

How control was concentrated—and treasury assets left

The record shows advance control, repeated multisig execution, specific notice, blocked recovery, retrospective ratification, and measurable investor harm.

Dossier conclusion

The evidence links pre-existing operational control to repeated treasury transfers, theft of staker fee rights, coordinated lending exposure, dismissal after specific notice, and governance action that preserved and later ratified the disputed change.

Control record

One funding root operated many apparent holders

Sovryn marketed direct Bitocracy control and user ownership while decisive powers remained with operational multisigs and a concentrated funding-and-voting network.

Direct source record

Statement

Public materials described a system directly controlled by Bitocracy and owned by its users, in which no single entity could make crucial changes.

Yago’s Bitocracy essay (opens in a new tab) · Sovryn fundraising statement (opens in a new tab)

On-chain record

Record

Exchequer retained both FeeSharing owner powers from October 2021. The live Guardian did not receive SIP-0047’s published seven-owner set. A strict B7-first-funded set supplied approximately 67.7% of source-attributed voting power.

Governance concentration and accountability votesThe defined set first funded through common funding wallet B7 supplied 67.7 percent of source-attributed voting power. Five linked wallets supplied every vote against SIP-0088.67.7%voting powerSIP-008862.6M linked votes againstRECOVERY DEFEATED100% of opposition linkedSIP-0089retrospective ratificationFeeSharing deployment wallet0xfEE171… cast 31.6M yes votes
Measured economic SOV exposure was approximately 21.7% of supply; this diagram shows voting power, not token ownership.

Concentration snapshot: Rootstock block 9,162,625 · 18 Aug 2026 17:55:21 UTC. Reader-facing percentages are rounded; the packet preserves the exact fixed-point result.

How one funding root became many apparent holders

Splitting tokens and votes among addresses can create the appearance of diversification in a holder list. The audit tests whether those addresses were operated together: one source paying their first transaction fees, immediate return transactions, long dormancy broken in common sessions, exact-value handoffs, aligned votes, and synchronized staking and borrowing.

B7 funding root and coordinated address activityA shared wallet requiring two of three owner approvals funded B7. B7 then made successful RBTC transfers to sixty-nine direct recipients. The defined first-funding set separately contains B7, fifty-four direct addresses, and fifteen indirect addresses. Ten previously unused core wallets immediately sent their first outgoing transaction back to B7. Wallets in the resulting set later acted together in voting, lending, and staking sessions.B7 ORIGIN WALLET2-of-3 approvals5.90 RBTCB7funding root69 DIRECT RECIPIENTS94 successful transfers10 FIRST-TX RETURNSrecipient keys → B767.7%voting power5 MATERIAL LOANS2022 + 2026STAKE SESSIONSwithdraw + rebuildStrict set: B7 + 54 direct-first-funded + 15 indirect-first-funded = 70 addresses.
B7 first funded each of the ten core wallets and immediately received each wallet’s first outgoing transaction. Later staking, borrowing, exact-value transfers, and voting converge on the same result: one centrally directed B7 operation.
On-chain record

The seed

shared wallet requiring two of three owner approvals at funding B7 origin wallet · 0x777e7f…aaf97f sent 0.01 RBTC and then 5.89 RBTC to common first-funder and coordinated-cluster root B7 · 0xb7d16f…ed81d8 on 20 November 2020.

0.01-RBTC funding transaction (opens in a new tab) · 5.89-RBTC funding transaction (opens in a new tab)

B7 origin-wallet approvals
Two of three owners were required when it funded B7. The recovered approvals on both transfers were supplied by origin-wallet creator and co-signer 01ad · 0x01ad90…9dd990 and origin-wallet co-signer and transaction submitter de25 · 0xde25ca…afc827 .
B7 activity
134 indexed transactions, including 94 successful simple transfers to 69 recipients. The packet’s strict first-funder methodology attributes 70 addresses to the B7 root, including B7 itself.
Two-way setup record
Ten previously unused core wallets funded in the February 2021 batch made their first outgoing transaction straight back to B7 only 1m13s–6m20s later. Their transaction-fee settings fall into three repeated groups.
What this establishes
Ten newly activated wallets sent value back to B7 within 73–380 seconds as their first outgoing transaction, using the same transfer limit and three repeated transaction-fee groups. This establishes one coordinated setup session.
On-chain record

Transaction record

Common first funding; one uninterrupted funding batch; ten immediate return transactions; repeated transaction-fee settings; exact-value handoffs; multi-wallet staking bursts; synchronized February withdrawals and restakes; concentrated, aligned voting; and later borrower-value consolidation.

Dossier conclusion

Coordination finding

The complete histories establish a centrally directed B7 operation. Low-frequency wallets repeatedly executed the same economic actions in narrow windows after long periods of inactivity.

Records authorities should compel

Responsibility chain

Public records place Yago, Nahari, and Tyrone in the leadership, accounting, and implementation roles surrounding this coordinated operation. Authorities should obtain custody logs, devices, delegate instructions, and communications to allocate each key and instruction.

Inspect the ten first outgoing return transactions to B7
Every previously unused core wallet sent its first outgoing transaction back to B7. A nonce is an account’s sequential outgoing-transaction number; nonce 0 means the first.
WalletB7 fundingFirst outgoing transactionReturnedDelayTransaction-fee price
February borrower; later RBTC hub b493 · 0xb493b1…a2c155 B7 outgoing transaction #51 (opens in a new tab)
12:01:06 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0001 RBTC 1m 40s 18387381
February borrower 5011 · 0x50110e…f07962 B7 outgoing transaction #53 (opens in a new tab)
12:05:31 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0001 RBTC 3m 4s 18387381
Large staker; transfer intermediary; recovery-opposition voter 78a0 · 0x78a0de…c0ffa7 B7 outgoing transaction #54 (opens in a new tab)
12:12:54 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0002 RBTC 1m 13s 18387381
February borrower 91ab · 0x91ab7f…021684 B7 outgoing transaction #55 (opens in a new tab)
12:16:46 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0002 RBTC 2m 46s 18387381
February borrower; former registered owner-address of the 0x924f Exchequer multisig; exact 2022 SOV handoff 4f39 · 0x4f3948…ae2e97 B7 outgoing transaction #56 (opens in a new tab)
13:09:53 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0002 RBTC 3m 29s 8468389
Legacy 2022 borrower; large staker; recovery-opposition voter 8d51 · 0x8d5158…be0fb7 B7 outgoing transaction #58 (opens in a new tab)
13:18:52 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0001 RBTC 1m 32s 8468389
Large staker; recovery-opposition voter; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e) a738 · 0xa7388d…3edce6 B7 outgoing transaction #59 (opens in a new tab)
13:32:47 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0002 RBTC 6m 20s 1008468389
Large staker; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e) 9369 · 0x93698c…08a12e B7 outgoing transaction #61 (opens in a new tab)
14:01:42 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0002 RBTC 4m 21s 8468389
Large staker; recovery-opposition voter 0d18 · 0x0d1831…238e91 B7 outgoing transaction #62 (opens in a new tab)
14:18:43 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0001 RBTC 1m 14s 1008468389
Current registered owner-address of the 0x924f Exchequer/Governor-guardian multisig and Contracts Guardian shared wallet dfd4 · 0xdfd4da…1eba62 B7 outgoing transaction #63 (opens in a new tab)
14:22:02 UTC
Recipient’s first outgoing transaction (opens in a new tab)
simple wallet transfer · success
≈0.0001 RBTC 1m 29s 1008468389

Why this is stronger than common funding: B7 paid the first transaction fees for ten recipients, and every recipient returned value to B7 within 73–380 seconds as its first outgoing transaction. Every return used the same simple-transfer limit, and the fee prices fall into three repeated groups. Together, those facts establish a coordinated setup session.

Inspect the complete-history activity profile
Complete Blockscout external-transaction histories for eleven key B7-linked wallets
Wallet and roleOutgoing transactionsTransaction-number rangeTransactions other than votesActive days other than votingLongest outgoing gap (rounded)
b493
February 2026 borrower
53 0–52
no missing outgoing nonces
22 12 301 days
5011
February 2026 borrower
55 0–54
no missing outgoing nonces
26 9 297 days
78a0
large staker · transfer intermediary
36 0–35
no missing outgoing nonces
20 8 297 days
91ab
February 2026 borrower
26 0–25
no missing outgoing nonces
21 10 512 days
4f39
February 2026 borrower · former owner of the 0x924f Exchequer multisig (2021–2023)
551 0–550
no missing outgoing nonces
527 176 298 days
8d51
legacy borrower · large staker
88 0–87
no missing outgoing nonces
57 25 282 days
a738
large staker
46 0–45
no missing outgoing nonces
16 11 297 days
52e8
former owner of the 0x924f Exchequer multisig; every outgoing transaction confirmed one of its transactions
49 0–48
no missing outgoing nonces
49 8 11 days
9369
large staker
40 0–39
no missing outgoing nonces
22 9 409 days
0d18
large staker
65 0–64
no missing outgoing nonces
24 13 297 days
dfd4
current owner of the 0x924f Exchequer/Governor-guardian multisig and the 0xdd8e Contracts Guardian shared wallet · large staker
52 0–51
no missing outgoing nonces
38 18 398 days
Low-frequency groupNine B7-first-funded core wallets other than February borrower and former Exchequer owner-address 4f39 recorded only 26–88 outgoing transactions and 8–25 distinct non-voting activity days across more than five years.
High-count exceptions explainedFebruary borrower and former Exchequer owner-address 4f39’s 551 outgoing transactions are dominated by confirmations for the 0x924f Exchequer multisig, which also guards both Sovryn Governor contracts. All 49 outgoing transactions from former Exchequer owner-address 52e8 confirm transactions for that same shared wallet.
Repeated convergenceAll ten core wallets staked on 18 October 2023; six acted in a staking-and-fee session inside 33m22s on 10 November 2024; all ten acted inside 97m20s on 29 September 2025; and eight consolidated inside 69m36s on 18 June 2026.

How activity was counted: the table covers complete Blockscout histories of transactions started by each address. Contract-generated transfer records are not counted again as separate wallet transactions. The result shows low-frequency wallets repeatedly making the same economic moves together after long inactive periods.

Open the linked-wallet explorer directory
B7 0xb7d16f650cb3b0754d61bdb3f6db79157ded81d8 Common first-funder and coordinated-cluster root
4f39 0x4f3948816785e30c3378ed3b9f2de034e3ae2e97 February borrower; former registered owner-address of the 0x924f Exchequer multisig; exact 2022 SOV handoff
b493 0xb493b1fb97f4cb2a1ea43a9ffed201e797a2c155 February borrower; later RBTC hub
8D51 0x8d515805a21743c2f2f33aa12a420907cbbe0fb7 Legacy 2022 borrower; large staker; recovery-opposition voter
78a0 0x78a0de7a48cce1a8759f353987731394d5c0ffa7 Large staker; transfer intermediary; recovery-opposition voter
A738 0xa7388d112406412f68c14e2924a070fd893edce6 Large staker; recovery-opposition voter; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e)
52e8 0x52e8f03e7c9c1ef320ff7c31db78eaead18e5f85 Former registered owner-address of the 0x924f Exchequer multisig; every outgoing call confirmed one of its transactions
9369 0x93698c0150d17b98b820e9c2fdcfa161d508a12e Large staker; delegates stake to the FeeSharing deployment/submission wallet and Exchequer signer (0xfEE171…4a9e7e)
0d18 0x0d1831ed7f1c5c55409a542d7e4bdda0c1238e91 Large staker; recovery-opposition voter
dFd4 0xdfd4da0e0e656af349e192b954baaef0fc1eba62 Current registered owner-address of the 0x924f Exchequer/Governor-guardian multisig and Contracts Guardian shared wallet
A7a4 0xa7a4a1afefdeadcb287769562fb65c3bbd83ccb6 Recovery-opposition voter; February restaker
de169 0xde1690480ef789beaa112157c7d123a5c85f6af2 Current registered owner-address of the 0x924f Exchequer/Governor-guardian multisig; FeeSharing approver; campaign signer

The complete 70-address attribution file publishes every full address, first-funding path, proof transaction, balance, and voting value. The complete-history coordination packet publishes the setup callbacks, address activity metrics, synchronized sessions, February linkage, methodology, and responsibility-record targets.

On-chain record

Common funding and coordination

Four February borrowers, the legacy borrower, large stakers, and a former Exchequer multisig owner were funded in one uninterrupted run of B7 transactions. In 2022, February borrower and former Exchequer multisig owner 4f39 · 0x4f3948…ae2e97 sent approximately 385,915 SOV to legacy 2022 borrower 8D51 · 0x8d5158…be0fb7 ; within 4m57s, 8D51 put the same underlying amount into three loans. The packet preserves the exact equality. Inspect the handoff (opens in a new tab) .

On-chain record

Guardian discrepancy

Zero of SIP-0047’s seven published Bitocracy Guardian signers was added to the live Guardian. In June 2026, Tyrone’s published role wallet sent and co-signed a valid owner rotation adding new owner wallets.

Dossier conclusionRecords authorities should compel

Allocate the coordinated operation

Authorities should obtain signer custody, delegate instructions, internal vote coordination, device/IP logs, and ownership records to assign each key and instruction within the established coordination pattern.

03 / Treasury theft

Treasury assets were stolen through repeated Exchequer multisig approvals

The Exchequer multisig was Sovryn’s shared treasury wallet. During this period, a transaction needed approvals from at least three registered owners. Twenty-seven material operations used that ordinary approval process and followed a small set of recurring routes over seven weeks.

Treasury asset routesThe 0x924f Exchequer multisig sent RBTC through transit wallet D9, then through Rootstock's Bitcoin bridge to the same terminal Bitcoin address. Other assets moved through conversion wallet 8C. Some reached the DD destination shared wallet; converted proceeds returned to the Exchequer multisig and later funded another D9 bridge transfer.0x924f EXCHEQUER3 of 8 during exits23.1464 RBTCD9Bitcoin transit walletBITCOIN BRIDGE23.1395 BTCSAME BTC ADDRESSexchange-style;customer unknownstables · DLLR · MOCBPRO · DOC8Cconversion + bridgeselected stable / bridge legsDD SHARED WALLETEthereum + BNB Chainconverted proceedsEXCHEQUER RETURN11.4877 RBTCBPRO / DOCJan legD9 TO BITCOINthrough bridge
Two main route families and a documented return path. Only selected stablecoins and bridged assets reached DD; converted MOC, DLLR, BPRO, and DOC proceeds returned to the Exchequer multisig and later moved through D9. The full addresses and transaction links appear directly below.
Concentrated Exchequer approvalsOnly four of eight historical owners of the Exchequer multisig approved any of the 27 material operations. The FeeSharing deployment wallet at 0xfEE171, named in Tyrone Johnson's official deployment record, approved all 27. The other three active owner wallets approved 21, 20, and 13.0xfEE171…4a9e7e27/270x9e9c0a…5dcf2221/270xa0fdcd…30ed8b20/270xeabb83…52a8613/27No other historical owner approved a curated exit
Each transfer used the Exchequer multisig’s ordinary approval path, requiring three registered owners. The FeeSharing deployment wallet at 0xfEE171…4a9e7e—named as sender in Tyrone Johnson’s official deployment record—approved all 27; the other labels are shortened Exchequer owner addresses.

Route explorers: Exchequer multisig 0x924f · 0x924f5a…2dc711 · Rootstock-to-Bitcoin transit wallet D9 · 0xd9ecb3…0a5d89 · conversion and bridge wallet 8C · 0x8c9143…84f50b supplied by the displayed Tyrone project account during the on-chain-matched May 2024 session · destination shared wallet on Ethereum DD · 0xdd2311…ee3fc4 · matching destination shared wallet on BNB Chain DD · 0xdd2311…ee3fc4 · FeeSharing deployment and Exchequer-submission wallet 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record

Value when the RBTC left the Exchequer: approximately $2.12 million. Using the closing BTC-USD price in the one-minute Coinbase Exchange candle containing each execution, 12 RBTC on 4 December 2025 was worth about $1,121,736; 6.7298 RBTC on 22 January 2026 about $605,630; and 4.4166 RBTC on 24 January 2026 about $395,314. Combined transfer-time estimate: $2,122,679.92. 4 December price (opens in a new tab) · 22 January price (opens in a new tab) · 24 January price (opens in a new tab) · method and arithmetic.

On-chain recordDirect source recordDossier conclusion

Treasury-linked DLLR redemptions forced Zero borrowers to surrender Bitcoin exposure

The investigation began with a narrower concern: treasury-linked DLLR was being turned into RBTC through Zero in a way that reduced Sovryn customers’ Bitcoin collateral exposure. At that point, the investigator did not yet know that the redemptions sat inside a much larger theft of usable treasury assets.

  1. 1
    Customers deposited BTC and borrowed a stablecoin.

    A Zero customer locked RBTC in a Line of Credit and minted ZUSD against it. DLLR could be converted into its backing asset, ZUSD.

  2. 2
    Treasury-linked value took the protocol-redemption route.

    Five Exchequer transactions sent approximately 569,214 DLLR to 8C. That wallet made matching DLLR-to-ZUSD calls and then eleven successful Zero redeemCollateral calls. First Exchequer DLLR exit (opens in a new tab) · last Exchequer DLLR exit (opens in a new tab) .

  3. 3
    Zero allocated the redemption against borrowers.

    Unlike an automated-market-maker sale, Zero’s redemption design (opens in a new tab) cancels the redeemer’s ZUSD and removes the oracle-priced RBTC equivalent from active Lines of Credit, beginning with the lowest-collateralized eligible positions. First successful Zero call (opens in a new tab) · last successful Zero call (opens in a new tab) .

Why that harmed Sovryn customers

Zero forced the timing of the collateral reduction. Each redemption reduced both debt and BTC collateral at the redeemer’s chosen moment, taking from borrowers the Bitcoin exposure they had used Zero to preserve.

The route also contracted ZUSD/DLLR supply instead of helping it grow. The dossier concludes that using treasury-controlled assets this way prioritized treasury conversion over minimizing harm to the protocol’s own users.

Attribution supported by the transaction record

The curated sequence records five treasury DLLR exits, five aggregator calls, eleven successful Zero redemptions, and approximately 6.2281 RBTC returned after the batches. The successful redemption inputs exceed the identified treasury DLLR because 8C held commingled balances. The attributable finding is a treasury-linked sequence; commingling prevents allocation of every redeemed ZUSD unit or returned satoshi solely to Exchequer DLLR.

Inspect the full transaction sequence and attribution limit.

The authority users had granted under SIP-0015

SIP-0015 (opens in a new tab) placed treasury funds in Bitocracy-approved multisigs, limited holdings in external systems to 10% for liquidity and price balancing, otherwise confined transfers to Sovryn protocol contracts or approved multisigs, and required approved budgets and reporting. The public audit located no record naming 8C, D9, DD, or the terminal Bitcoin address as an approved custodian. Any claimed private authorization should be produced with the budgets, instructions, signer records, custody records, and accounting required to substantiate it.

Direct source record

Yago’s explanation

Yago later described the activity as an “overall consolidation that we did of the treasury.”

The question specifically raised the December–January DLLR conversions. Yago said Sovryn wanted to hold most treasury funds in BTC because “the project does the same.” Community Call #72, beginning at 43:52 and continuing at 46:40.

On-chain record

What the public wallet record showed

By the time of the call, the Exchequer multisig held only 0.7134 RBTC. The record traces approximately 23.1464 RBTC—worth approximately $2.12 million when the three transfers left the Exchequer—through the Rootstock-to-Bitcoin transit wallet (D9) to one exchange account address; about $522,242 in reconciled stablecoin receipts, 12.12 ETH, and 52.85 BNB reached the cross-chain destination shared wallets (DD). No public ledger has reconciled those off-wallet holdings back to Sovryn.

The description of consolidating the treasury into BTC does not match the visible destinations and asset mix. All 27 operations used valid Exchequer multisig approvals. FeeSharing deployment wallet and Exchequer signer; 27 approvals 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record approved all 27. Three other registered Exchequer owner-addresses— Exchequer owner-address; 21 approvals 0x9e9c0a…5dcf22 · 0x9e9c0a…5dcf22 , Exchequer owner-address; 20 approvals 0xa0fdcd…30ed8b · 0xa0fdcd…30ed8b , and Exchequer owner-address; 13 approvals 0xeabb83…152a86 · 0xeabb83…152a86 —completed the active signer group.

Inspect the underlying DD and BOS custody record
Direct source recordOn-chain recordDossier conclusionRecords authorities should compel

Cross-project custody record

The DD treasury destination shares its control network with BitcoinOS

DD received assets routed from Sovryn’s Exchequer. Matching DD Safes on Ethereum and BNB Chain were configured with the same five owner addresses as the Safe that owns the official BOS token and the Safes holding BitcoinOS’s published allocation buckets. The record establishes shared custody, signer, deployment, and payment infrastructure across Sovryn treasury activity and BitcoinOS token administration.

  1. Separation asserted; a contribution path contemplated

    Yago wrote, “Sovryn has not been funding BitcoinOS” (opens in a new tab) , described separate contributors and funding, and later said “Sovryns treasury is not being requested for anything.” (opens in a new tab) He repeated the distinction on Community Call 63 (opens in a new tab) . On 2 July he added that, for Sovryn to receive 10%, it would need to “invest between $5m-$100m in value or provide in-kind value to that degree” (opens in a new tab) and actively help raise BOS funds.

  2. Official contributions acknowledged

    SIP-0083 (opens in a new tab) said Sovryn had made substantial contributions throughout BitcoinOS development and committed Sovryn resources to technical development, audits, interfaces, marketing, infrastructure, and network operations. Yago then called Sovryn a significant BitcoinOS participant (opens in a new tab) .

  3. Cross-payments admitted; mingling denied

    Yago said funds had been “paid out by BOS on behalf of Sovryn” (opens in a new tab) and needed year-end consolidation. Minutes later, asked whether Sovryn was mingling funds with BOS, he answered “No.” (opens in a new tab) The shared-key and payment record below requires a transaction-level reconciliation of those statements.

Asset route

  1. Sovryn Exchequertreasury-derived assets
  2. 8C and bridge routesconversion and deployment layer
  3. DD on two chains2-of-5 destination and payment Safes

Owner-address linkage across time

  1. B7Rootstock · Dec 2020 · 0.1 RBTC
  2. 0x509201…AbD6cross-chain operations address
  3. 0x5C07…96C2Ethereum first funding · Oct 2025 · 0.05 ETH

Control overlap

  1. 8C deployerDD and BOS Safe families
  2. Same five owner addressesrepeated 2-of-5 control set
  3. BOS administrationtoken owner and allocation Safes

01 · One control set

DD and the BOS Safe family use the same five owner addresses

8C created Ethereum DD (opens in a new tab) 63 seconds after creating its matching BNB Chain Safe (opens in a new tab) , using identical setup data, the same five owners, and a 2-of-5 threshold. The same 8C wallet created the Safe that owns the official Ethereum BOS token (opens in a new tab) and the allocation Safes with that exact owner set.

The initial BOS balances reconcile the official schedule: 6.72 billion BOS, exactly 32%, reached the inferred ecosystem Safe; three inferred founding-entity Safes received 7.35 billion BOS, exactly 35%, after accounting for their 100-BOS tests and 50-BOS returns. Official allocation schedule (opens in a new tab) · allocation execution (opens in a new tab) .

02 · Long-running operational continuity

0x509201…AbD6 links B7, Sovryn’s bridge, payments, DD, and BOS

B7 sent 0.1 RBTC to 0x509201…AbD6 in December 2020 (opens in a new tab) . The same address later sent at least 8.55 million USDT across 18 transfers to the official Sovryn Ethereum bridge (opens in a new tab) , solely controlled an earlier recurring-payment Safe, approved every observed Ethereum DD execution, and is listed throughout the BOS Safe family.

Five external recipients from that earlier CSV-style recurring-payment record (opens in a new tab) reappeared together in DD’s December 2025 batch. That functional continuity is stronger than a shared-wallet-format resemblance: it connects the operator key and recipient network across years.

The later BOS sale-wallet reconstruction adds direct proceeds links: the post-maintenance Ethereum collector transferred 204,103.50752 USDT, 30,056.588245 USDC, and 3.605528 ETH to 0x509201, while its Rootstock instance sent swept participant RBTC into Sovryn’s Exchequer.

03 · Concentrated execution

The same pair approved all 14 Ethereum DD executions

0x509201…AbD6 and 0xcD9003…fBAA supplied every observed Ethereum DD quorum. DD then sent 70 ETH on 1 December 2025 (opens in a new tab) and 120,000 USDT on 30 March 2026 (opens in a new tab) directly to 0x509201…AbD6; the recipient approved both payments and 0xcD9003…fBAA supplied the second signature.

On BNB Chain, DD’s executed transaction used 0x509201…AbD6 with 0x5C07…96C2 . The five addresses are Safe owner addresses, not five identified independent people.

Inspect the five owner addresses and their demonstrated roles
Operational labels follow demonstrated transactions. The natural-person controller of each key remains unidentified in the reviewed public record.
Owner keyEvidence-based roleDemonstrated basisHuman controller
0x5092019A3E0334586273A21a701F1BD859ECAbD6 Long-running Sovryn and BitcoinOS treasury-linked operational owner address; recurrent DD signer and DD payee
Confidence: very high
Received RBTC from B7; sent 18 USDT transfers totaling 8,550,668.522386 USDT to Sovryn's official Ethereum bridge; solely controlled the earlier recurring-payment Safe; provisioned three later shared owner addresses; approved every Ethereum DD execution; received 70 ETH and 120,000 USDT from DD; and is listed throughout the BOS Safe family. unidentified
0xcD90036b1b1E2576E380Fa407Cb8021f4f4efBAA Principal BitcoinOS/DD owner address and recurrent DD co-signer
Confidence: very high
Supplied the second approval on every observed Ethereum DD execution and is listed throughout the related BOS and DD Safes. unidentified
0x5C07E4CC17e3d6076fc7963235B1e3299b1596C2 Shared DD/BOS owner address and BNB DD co-signer directly provisioned by 0x509201…AbD6
Confidence: high
Co-approved the observed BNB Chain DD execution and is listed throughout the DD/BOS Safe family. The address has no located Rootstock activity; its B7 relationship is the proved two-hop path through 0x509201…AbD6. unidentified
0xe31cfdF3C6E4FE91f8873227e025725bb9dF67C6 Lightly used shared DD/BOS owner address provisioned by 0x509201…AbD6
Confidence: high
0x509201…AbD6 supplied its first Ethereum funding; the address is listed throughout the exact five-owner DD/BOS Safe family. unidentified
0x59c4d24687f5eE6C846Df010a49b55281d2Ded0f Lightly used shared DD/BOS owner address provisioned by 0x509201…AbD6
Confidence: high
0x509201…AbD6 supplied its first Ethereum funding; the address is listed throughout the exact five-owner DD/BOS Safe family. unidentified

Cross-project finding

The record establishes shared cross-project operational control and cross-project financial flows. Sovryn treasury-derived assets reached DD; DD and the official BOS control wallets used the same five owner addresses and the same 8C deployer; the two recurring DD approvers are listed throughout the BOS Safe family; and the central 0x509201…AbD6 address connects B7, Sovryn’s official bridge, recurring organizational payments, DD payments, and BOS token operations.

Whether those flows were properly authorized, allocated, reimbursed, commingled, or misappropriated requires the complete ledgers. Authorities should investigate embezzlement, misallocation, undisclosed related-party transfers, and false accounting by obtaining the Sovryn and BTC OS Limited ledgers; intercompany agreements and reimbursement entries; DD invoices, payroll, vendors, and project allocations; the five addresses’ beneficial controllers; and the source and use of every BOS-on-behalf-of-Sovryn payment.

Inspect the complete control-topology and source record.

Direct source record

What leadership said when the customer harm was asked directly

On Community Call #73, Yago was asked why the treasury route redeemed against users rather than using another conversion path. He said he was not involved in that choice. Nahari said he could not recall the exact reason and suggested it might have concerned BabelFish liquidity.

Later in the same call, continued questions were characterized as baseless, conspiratorial, noise, bad faith, and a failure to understand—without a transaction-level ledger that reconciled the challenged routes.

Dossier conclusion

Why the later record changes the meaning of those answers

The initial complaint concerned a specific customer-protection problem. Only later did the wallet record reveal the larger treasury theft and multiple destination routes. The explanations then expanded from ordinary consolidation into BTC, to exchange payments and a general FastBTC-liquidity account, while the reason for choosing Zero redemptions against users remained unreconciled.

This victim-led dossier concludes that the repeated omission of material context, shifting explanations, and dismissal of evidence amounted to deception and gaslighting. Investors experienced each new discovery as another reason to doubt assurances they had already been given. The public record proves the statements and the unreconciled sequence; private communications and account records remain necessary to determine each person’s intent and instruction.

Direct source record Community Call #73 · 01:00:32–01:02:10.900

Complete question and answer containing the inability to explain the precise redemption method

Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked

Direct source record Community Call #73 · 01:08:46–01:11:33.400

Complete question and answer containing the bad-faith, lack-of-understanding, and no-deep-mystery response

Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked

Two distinct RBTC flows: November FastBTC and the later 23.1464-RBTC route

On-chain recordDirect source recordDossier conclusionRecords authorities should compel

The stolen RBTC reached one exchange deposit address

bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5 (opens in a new tab)

Nahari confirmed the destination type

“It is an exchange wallet. It has nothing to do with OKX.”

That Community Call #73 statement turns “exchange destination” from a third-party label inference into a direct management acknowledgment. Nahari then described centralized exchanges as being used to swap assets for payments and supplied the broader FastBTC-liquidity account.

What that admission supports

Nahari’s specific knowledge establishes that leadership recognized the exchange destination and asserted a business purpose for it. Exchange KYC and account records can identify the credited customer, beneficial owner, trades, withdrawals, and fiat proceeds.

OKLink labels the terminal address Gemini (opens in a new tab) . A directly connected consolidator carries an OKEx label on BitInfoCharts (opens in a new tab) . Together with Nahari’s explicit denial of OKX, Gemini is the leading public venue inference, not a settled identification. Exchange account and customer-identification records are required to resolve it.

Bitcoin receipts into the same terminal address. The November FastBTC flow remains analytically separate from the later Exchequer route.
RouteTerminal receipt (UTC)BTCBitcoin transaction
November FastBTC route 1 ≈4.13 0d7c9836b5…9098e8
November FastBTC route 2 ≈7 8ee46e3c42…2f6703
December Exchequer route ≈11.999 45f6e40a5c…d2b173
22 January Exchequer route ≈6.7205 f753d78eba…fba93e
24 January Exchequer route ≈4.42 dd5b45fe83…6efdc4

Convergence proved; customer identity unresolved. The two November receipts total approximately 11.1299 BTC. The three later receipts total approximately 23.1395 BTC. All five terminate at the address above; only the exchange can identify the credited account, controller, and beneficial owner.

Direct source record

Statement

On Call #73, Nahari confirmed the destination was an exchange wallet, denied it was OKX, and supplied a general third-party FastBTC-liquidity explanation for exchange-bound movements. He referred to roughly 80–100 BTC across the systems.

On-chain record

Record

November FastBTC sources sent approximately 11.1212 RBTC into the Rootstock-to-Bitcoin transit wallet (D9). The later Exchequer route sent a separate approximately 23.1464 RBTC—worth approximately $2.12 million at the transfer times—in December and January. A payment or liability of that scale should be supported by a named counterparty, agreement, invoice, authorization, liability ledger, and transaction mapping. The public explanation supplied none of them.

Records authorities should compel Obtain the complete FastBTC accounting packet and both Rootstock- and Bitcoin-side liability records.

Exchequer transaction ledger · 27 operations
Exchequer multisig primary and terminal asset exits, 4 Dec 2025–24 Jan 2026. Approvers are shown as shortened, explorer-linked wallet addresses.
UTC / blockAsset / amountRouteIDApproversExecution

#8,275,774
≈12 RBTC D9 / PowPeg route
Rootstock-to-Bitcoin transit wallet D9 0xd9ecb3…0a5d89 · 0xd9ecb3…0a5d89
2099 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 0xf09e5dde…a7d1d6

#8,276,441
≈200,000 XUSD 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2101 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b 0x07052fa1…f4973c

#8,277,370
≈202,460 XUSD 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2102 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 0x78deb5f3…f57506

#8,277,710
≈200,000 MOC 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2103 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xeabb83…152a86 0x032087d6…29142e

#8,279,785
≈363,500.89 MOC 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2104 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b 0x495f862c…65ffd5

#8,290,267
≈0.14 ETHes ETH bridge to DD (0.1302 ETH after fee)
destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4
2106 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b 0xc6f569df…acddac

#8,291,602
≈12 ETHes ETH bridge to DD (11.99 ETH after fee)
destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4
2114 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 0xcaa7c69e…ad6c9a

#8,298,386
≈100,000 DLLR 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2123 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 0x2c78a6ef…13b41e

#8,299,259
≈2.09 BNBbs BNB bridge terminal receipt 2.085 BNB
destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4
2131 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b 0x42dcbd61…231e9a

#8,299,262
≈0.78 BNBs BNB bridge terminal receipt 0.772639178690725711 BNB
destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4
2132 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b 0xbbc42bfc…f7cb65

#8,301,076
≈100,000 DLLR 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2135 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b 0x298ea984…7bf16b

#8,301,277
≈50 BNBbs BNB bridge terminal receipt 49.996 BNB
destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4
2137 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 0xd47074af…44e3fb

#8,321,340
≈100,000 DLLR 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2138 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b 0x061e0602…aefc2b

#8,324,949
≈794,380 SOV FeeSharing deployment wallet and Exchequer owner-address
0xfee171…4a9e7e
2139 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0xeabb83…152a86 0x3c72607f…84282d

#8,326,566
≈46.01 ETHes ETH bridge request; far-side receipt not located
destination shared wallet DD 0xdd2311…ee3fc4 · 0xdd2311…ee3fc4
2141 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 0x4a4af853…7a2b02

#8,326,568
≈100,000 DLLR 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2142 0xfee171…4a9e7e · 0xeabb83…152a86 · 0x9e9c0a…5dcf22 0xa0b1bd1f…f65e61

#8,342,107
≈169,214 DLLR 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2144 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xa0fdcd…30ed8b 0x5661bbfa…0797fa

#8,342,801
≈687,320 SOV Exchequer owner-address 0x9e9c0a…5dcf22
0x9e9c0a…5dcf22
2145 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 0x12dc23cb…adda6d

#8,351,352
≈11,710 USDCes 8C bridge/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2151 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 0xab016cdb…8000ff

#8,351,352
≈1,650 USDCbs 8C bridge/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2152 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 0x87f9c88d…46b8ff

#8,351,353
≈13,260 USDTes 8C bridge/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2153 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 0xeff95ec1…548ae5

#8,351,358
≈5,400 USDTbs 8C bridge/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2154 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 0xbf0f08ec…e446e9

#8,440,529
≈100,000 rUSDT 8C bridge/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2156 0xfee171…4a9e7e · 0xa0fdcd…30ed8b · 0x9e9c0a…5dcf22 0x8d135d4b…d433a9

#8,447,816
≈6.7298 RBTC D9 / PowPeg route
Rootstock-to-Bitcoin transit wallet D9 0xd9ecb3…0a5d89 · 0xd9ecb3…0a5d89
2157 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b 0xc9f566be…a96127

#8,448,302
≈3.65 BPRO 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2162 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b 0xea3646c2…4809a3

#8,448,306
≈55,000 DOC 8C converter/custody
conversion and bridge wallet 8C 0x8c9143…84f50b · 0x8c9143…84f50b
2163 0xfee171…4a9e7e · 0xeabb83…152a86 · 0xa0fdcd…30ed8b 0x7c176380…080a12

#8,454,487
≈4.4166 RBTC D9 / PowPeg route
Rootstock-to-Bitcoin transit wallet D9 0xd9ecb3…0a5d89 · 0xd9ecb3…0a5d89
2164 0xfee171…4a9e7e · 0x9e9c0a…5dcf22 · 0xeabb83…152a86 0x336a6d72…6bdd5f
On-chain record

Gross on-chain asset estimate for 1 December. A realized-output valuation puts the material non-SOV assets at $2.66 million. Valuing the approximately 5.07 million SOV balance with Sovryn’s on-chain reference price adds about $536,947, for a reproducible gross estimate of about $3.20 million. A separate same-time price check reached $3.25 million. These are asset values before unidentified liabilities or off-chain accounts. BTC price (opens in a new tab) · ETH price (opens in a new tab) · BNB price (opens in a new tab) · balances, realized outputs, and valuation method.

By 18 August, the Exchequer multisig held 0.7134 RBTC and approximately 3.44 million SOV; selling that entire SOV balance through the only identified exchange pool quoted approximately 0.5029 WRBTC. The theft had left Sovryn with effectively no usable, diversified on-chain liquidity. The public packet keeps every input and values SOV separately so its thin market is not treated like cash.

Records authorities should compel

Records needed to complete the treasury accounting

  • Exchequer minutes, internal votes, budgets, and signer instructions
  • Centralized-exchange customer-identification, subaccount, deposit, trade, and withdrawal records for the Bitcoin cluster
  • Signer identities and custody records for 8C and all five shared DD/BOS owner addresses, plus DD payee schedules, Safe execution records, and beneficial-controller mapping
  • Sovryn and BTC OS Limited general ledgers, intercompany accounts, journal entries, cost allocations, reimbursements, invoices, payroll, processor contracts, and bank/exchange statements
  • FastBTC agreements, provider identities, beginning/ending liabilities, and payment reconciliation
  • Destination-side proceeds tracing, BOS allocation and vesting records, and every related-party or BOS-on-behalf-of-Sovryn payment record

Part II · Investor harm

Sovryn promoted Bitcoin income—then took the fees

Sovryn promoted staking as a way to earn Bitcoin and stablecoin revenue. Sixteen days after its January solicitation, a Tyrone-linked deployment workflow shut live fee claims. In February, the Exchequer multisig replaced the contract code and stole stakers’ rights to all newly recorded RBTC and ZUSD fees before any Bitocracy vote.

Official Sovryn X post dated January 12, 2026 saying Stake SOV right now to earn up to 21.37 percent APR BTC and USD
Official Sovryn solicitation · 12 January 2026. “Stake SOV right now to earn up to 21.37% APR BTC and USD.” Captured from X’s official post renderer (opens in a new tab) . Full-image SHA-256: 2955fb83…457755e4.
Direct source recordOn-chain recordDossier conclusion

Why this is evidence of deceptive solicitation and investor damage

The advertisement used a present-tense instruction to enter the staking proposition: lock SOV now and receive Bitcoin and dollar-denominated revenue. Sovryn’s product page (opens in a new tab) , earn page (opens in a new tab) , and staking article (opens in a new tab) repeated the same economic promise.

Sovryn publicly identified Yago as project lead. He designed and joined the small Exchequer framework, announced the revenue redirection documented here as theft, repeatedly described what “we” decided, defended executive action before a vote, and sponsored its later ratification. The official advertisement and the later theft therefore belong to the same leadership and policy record.

Yago personally promoted the same investment logic. In December 2024 he wrote that SOV paid yield from protocol revenue “primarily in the form of BTC” and that making returns more obvious would increase staking desirability. At 13:58 UTC on 17 February 2026—twelve minutes before the pause announcement—he wrote that staking should remain “compelling long-term” and that staker distributions should come from “real revenue.” Read the 2024 statement (opens in a new tab) · read the 17 February statement (opens in a new tab) .

  1. Solicitation: Sovryn told readers to stake immediately for up to 21.37% APR in BTC and USD.
  2. Undisclosed live intervention: FeeSharing deployment and Exchequer-submission wallet 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record deployed code that disabled fee claims; enough owners of the Exchequer multisig 0x924f · 0x924f5a…2dc711 activated it that day.
  3. Leadership announcement: Yago announced the pause and the revenue redirection documented here as theft after the operational path had already been used on mainnet.
  4. Staking-revenue theft executed: the Exchequer multisig activated the replacement code. The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e then added RBTC and ZUSD to the 100%-withholding list by 11:44:51. Tyrone’s official deployment record names this wallet as its sender. The vote came later.

The same promise remained live after the staking-revenue theft

Captured on 20 August 2026—nearly six months after the Exchequer multisig activated 100% withholding—the official staking page still said “up to 20% APR,” “rewards you in BTC,” and “PAYOUTS IN BTC,” beside a “BUY SOV” action. The archived HTML begins with Webflow metadata reading “Last Published: 9 February 2026,” after the January claim shutdown and before Yago’s 17 February notice.

Official Sovryn staking page captured August 20, 2026 advertising up to 20 percent APR and rewards in BTC
Official site capture · 20 August 2026. “Up to 20% APR” and “rewards you in BTC.” Open the live source (opens in a new tab) · SHA-256 3e9cba85…25a33a0.
Official Sovryn staking page captured August 20, 2026 showing Payouts in BTC and a Buy SOV button
Official site capture · 20 August 2026. “PAYOUTS IN BTC” beside “BUY SOV.” SHA-256 40740fde…37d8c6.

Current mismatch: the official page continued soliciting staking with BTC-return language while the active contract routed listed RBTC and ZUSD fees away from staker claim accounting. This continued publication is direct evidence for the deception, materiality, reliance, and damages inquiry.

Direct source recordDossier conclusion

Representation and inducement

The official account told readers to “Stake SOV right now” for BTC and USD returns. Yago had already described BTC revenue as the basis of SOV yield and as something that made staking desirable.

On-chain recordDossier conclusion

Capital committed while the message was live

Between the 12 January promotion and Yago’s 17 February notice, 15 beneficiary wallets directly staked approximately 111,068 SOV. 20 wallets extended locks covering approximately 9,962,956 SOV. The extension total measures already-locked positions, not new purchases.

Read the method · inspect every transaction.

Direct source recordOn-chain recordDossier conclusion

Knowledge, control, and omission

The Exchequer multisig used its retained power to stop claims on live mainnet on 28 January. Yago later said “we” had decided on the revenue redirection documented here as theft and defended executive action before a vote. The promotion and official staking pages did not explain this retained control, and the staking page continued advertising BTC payouts after 100% withholding went live.

On-chain recordDossier conclusionRecords authorities should compel

Loss and investor files

The replacement code stole stakers’ rights to approximately 0.2912 RBTC and 12,215 ZUSD by excluding those fees from claim accounting as of the 18 August snapshot. Each victim file should connect the dated representation to purchases, staking or lock extensions, fees received, remaining holdings, and realized or continuing loss.

Who controlled staker fees and when governance votedThe Exchequer multisig held both administrative controls since 2021, shut fee claims for forty-four hours in January 2026, activated one hundred percent withholding in February before a vote, and Yago later sponsored retrospective ratification.OCT 2021both owner roles28–30 JAN 202644h20m claim freeze25 FEB100% withholding liveno prior Bitocracy vote23 MAR+ratification proposed
At block 9,162,805, the newly withheld RBTC and ZUSD remained in the contract’s internal accounting records with zero withdrawal events.

What the contract record shows: measured at Rootstock block 9,162,805 on 18 August 2026, both administrative-owner checks still pointed to the Exchequer multisig 0x924f · 0x924f5a…2dc711 . The totals from 90 RBTC and 46 ZUSD fee events exactly matched the contract’s internal accounting records; no withdrawal event was recorded.

Direct source record

Yago’s public explanation

“The answer is very simple. It’s because it happened. So we don’t know in advance what is going to happen… Now that it has happened, we’re taking action again.”

Community Call #72, answering why the Bitcoin decline caused the response.

On-chain record

The earlier action and price record

The live claim shutdown was deployed on 28 January at 15:29 UTC and activated at 17:51 UTC. Coinbase candles place BTC near $89,139 at deployment and $90,350 at activation. The larger daily decline followed: the 28 January close was about $89,162; the 29 January close was about $84,513, down 5.2%. Inspect the daily candles (opens in a new tab) .

The 29 January fall could not have first triggered the 28 January action. The same retained administrative route had already been prepared and used to stop claims on live mainnet. Yago later cited the recent BTC decline when justifying the February change that stole staker fee rights. Inspect the Coinbase interval (opens in a new tab) · inspect Tyrone’s January code record (opens in a new tab) .

Direct source record Community Call #72 · 00:43:38–00:46:27

Complete question and answer on the treasury reaction, BTC exposure, and replenishment

Watch the full Community Call #72 on YouTube (opens in a new tab) · source recording and captions checked

Direct source record

Yago’s later position

Yago later said FeeSharingCollector had never been—and was never intended to be—controlled by Bitocracy. Read Yago’s FeeSharing response · 8 March 2026 (opens in a new tab) .

On-chain record

Earlier governance expectation and actual power

SIP-0046 stated that FeeSharingProxy was an exception to Exchequer ownership (opens in a new tab) . Chain history shows both administrative roles for the live FeeSharing contract transferred to the Exchequer multisig in October 2021 and remained there through the February theft.

Direct source record

Code and deployment

Tyrone Johnson authored the January shutdown and February withholding code. His official deployment commit records FeeSharing deployment and Exchequer-submission wallet 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record as sender. That wallet submitted the Exchequer multisig code replacement 51 seconds later and the RBTC/ZUSD operations during the next 2m25s. Inspect the official deployment record (opens in a new tab) .

On-chain record

Execution

Enough owners of the Exchequer multisig approved the replacement code. It went live on 25 February; RBTC and ZUSD were placed on the 100%-withholding list. No prior Bitocracy proposal was located.

On-chain recordDossier conclusion

Measured staking revenue stolen from staker claim accounting

The code excluded approximately 0.2912 RBTC and 12,215 ZUSD from the accounting entries that let stakers claim fees. Those amounts remained under an Exchequer-controlled withdrawal function.

Dossier conclusionRecords authorities should compel

How this record supports a fraud referral and investor damages

The official solicitation, undisclosed retained control, pre-announcement mainnet intervention, Yago’s announcement, defense, and ratification sponsorship, continuing post-theft marketing, and measurable theft of fee rights form a documented deceptive-inducement record. Each investor’s loss schedule should connect the public evidence above to:

  • SOV purchase transactions, dates, quantities, and prices
  • Staking transactions, lock duration, expected fees, and actual fees received
  • The advertisement or revenue statement the investor saw and when they relied on it
  • Unstaking or sale transactions, current holdings, and the method used to value the loss
  • Messages, call recordings, or forum posts showing what leadership knew and when
  • Internal campaign approval, FeeSharing planning, Exchequer multisig instructions, and analytics showing who targeted or viewed the promotion

Submit purchase, staking, reliance, and loss records through the encrypted evidence intake.

FeeSharing transaction ledger · 15 entries
FeeSharing transaction chronology · full hashes in the public packet
UTC / blockWhat happenedTransaction

#3,769,580
The contract was created with the deployer holding both administrative roles 0x92560ba4…245e5e (opens in a new tab)

#3,769,600
First owner role transferred to Exchequer 0xdb6f399d…dc1d26 (opens in a new tab)

#3,769,602
Second owner role transferred to Exchequer 0xd095df4d…4c3312 (opens in a new tab)

#8,469,257
The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e deployed code that disabled staker fee claims 0x6fa7f9ca…f306a7 (opens in a new tab)

#8,469,265
The 0xfEE171…4a9e7e deployment wallet submitted the claim-shutdown request as Exchequer multisig transaction 2166 0x0fd70e59…22be1a (opens in a new tab)

#8,469,615
Enough Exchequer multisig owners approved and activated the claim shutdown 0xedc2cf4b…d93e96 (opens in a new tab)

#8,475,868
The 0xfEE171…4a9e7e deployment wallet submitted Exchequer multisig transaction 2167 to restore the earlier code 0xec720d14…d1d071 (opens in a new tab)

#8,475,916
Enough Exchequer multisig owners approved and restored claims after 44h20m01s 0x1ba84692…52a33b (opens in a new tab)

#8,544,919
The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e deployed the 100%-withholding code 0x6b281895…696e96 (opens in a new tab)

#8,544,922
The 0xfEE171…4a9e7e deployment wallet submitted the code replacement as Exchequer multisig transaction 2196 0x9c78c855…9a947b (opens in a new tab)

#8,544,924
The 0xfEE171…4a9e7e deployment wallet submitted 100% RBTC withholding as Exchequer multisig transaction 2197 0x4d9d1306…162601 (opens in a new tab)

#8,544,926
The 0xfEE171…4a9e7e deployment wallet submitted 100% ZUSD withholding as Exchequer multisig transaction 2198 0x01c6a7b8…a7c431 (opens in a new tab)

#8,565,302
Enough Exchequer multisig owners approved and activated the replacement code 0x1c8293f9…481c60 (opens in a new tab)

#8,565,356
The 0xfEE171…4a9e7e deployment wallet executed the RBTC 100%-withholding addition 0x994d2cac…04d8ba (opens in a new tab)

#8,565,358
The 0xfEE171…4a9e7e deployment wallet executed the ZUSD 100%-withholding addition 0x33b47515…fe1138 (opens in a new tab)

Loans and lender harm

Linked wallets borrowed Bitcoin against illiquid SOV

The February loan session joined synchronized stake withdrawals, four B7-linked openings, and coordinated restaking. It was not the cluster’s first lender exposure: a legacy position opened in 2022 now accounts for most of the estimated shortfall. The located record contains no closure, pause, repayment demand, committed cure, or independent risk action before liquidation. The calculations assume no borrower repayment, new capital, insurance, or outside rescue.

B7-linked loan sequence and harmB7 first funded four wallets. They opened loans over fifteen minutes and twelve seconds, received 1.465 RBTC, and their addresses were publicly listed. Nine later liquidations struck three positions while all four remained active and below Sovryn's required collateral level at the snapshot.B7first-funding rootFEBRUARY BORROWER WALLETS91AB4f39b493501115m12s1.465 RBTCborrower payoutsAUGUST SNAPSHOT9 liquidations4 active + unsafe1.1151 WRBTC owed
Four February loans are part of a larger five-loan linked impairment. The legacy 0x839c… loan—not the February set alone—dominates the current shortfall.

Four-loan outcome snapshot: Rootstock block 9,158,536 · 17 Aug 2026 07:23:15 UTC. The separate all-eleven model for the iWRBTC lending pool is pinned to block 9,162,594.

On-chain record

The coordinated February loan sequence

Seven B7-first-funded wallets withdrew more than 10 million SOV; four opened SOV-backed loans, and Yago’s staking-revenue announcement followed the final opening by 12h35m18s.

  1. Seven linked wallets withdrew approximately 10,048,901 SOVFour acted inside 7m13s. Three more followed 1h38m later; the first three transactions in the opening group used the same gas price and gas limit.
  2. Four of those wallets opened loans inside 15m12sEach borrower had withdrawn matured stake 186–7,083 seconds earlier. The borrow calls supplied approximately 7,006,709 SOV, and the borrowers received 1.465 RBTC net.
  3. Yago announced the staking-revenue change The reward pause and the change documented here as theft (opens in a new tab) followed the fourth loan opening by 12h35m18s.
  4. Linked wallets rebuilt long-duration stakes togetherThree non-borrowers restaked the exact amounts they had withdrawn. With three other linked wallets, approximately 6,986,587 SOV entered stakes inside 43m16s; five used the same 16 February 2029 lock target.

Dossier conclusion The withdrawals, loan openings, reward announcement, exact-value restakes, shared lock targets, and repeated prior sessions establish a coordinated sequence supporting investigation of advance knowledge and conflicts. Custody, instruction, and internal planning records can allocate the people directing it.

Direct source record

8 March 2026

Public notice

Dossier conclusionRecords authorities should compel

Warning and evidence delivered

Public Disclosure #2 (opens in a new tab) listed the four borrow transactions, tied their timing to the reward announcement, warned that illiquid collateral endangered RBTC lenders, asked Yago and Nahari to close the loans immediately, and requested stronger collateral rules.

Power to act
Leadership could call for repayment, initiate an independent risk investigation, support a pause or rule change, disclose control and conflicts, or back the requested governance remedy.
Recorded response
On Call #73 Yago disclaimed relevance and said SOV owners could do what they chose.
Omitted
No commitment to close the loans, require repayment, pause exposure, investigate coordination, or protect existing RBTC lenders.
Protective action not taken
The four loans remained open; no later collateral deposit occurred.
Later on-chain outcome
Nine August liquidations seized approximately 1.57M SOV; all four positions remained active and unsafe with approximately 1.1151 WRBTC outstanding.
Why the dossier infers intent
Specific notice, ability to mitigate, dismissal, continued inaction, and the later predicted harm support an inference of knowing disregard.
Records to compel
Borrower-key custody, internal notice, risk review, repayment instructions, and all communications from 17 February through the August liquidations.
Later confirmation
Disclosure #4 (opens in a new tab) documented liquidation and the continuing pool impairment.
Direct source record Community Call #73 · 00:42:54–00:43:40

Yago responds when the founding-member loan is raised

Excerpt checked against the full call

“No, of course not. What’s it got to do with me? Or the conversation that we’re having? Like, people who own SOV can do with it whatever they choose.”

Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked

Direct source record

57:40–58:40 follow-up

The question explicitly stated Sovryn’s responsibility to protect RBTC lenders from losses caused by illiquid collateral.

Dossier conclusion

What the answer did

Yago shifted the remedy toward future collateral-rule changes. He supplied no commitment to close the identified loans, require repayment, pause the risk, disclose conflicts, or begin an independent investigation.

Loan transaction ledger · 4 openings and 9 liquidations
Linked loan openings · 17 Feb 2026 · 15m12s from first to last
UTC / blockBorrower / loanPrincipalCollateralTransaction

#8536319
0x91ab7f…021684
0xeb0bb06d…949ebf
≈0.3862 WRBTC ≈1,839,490 SOV 0xb55fb894…fcc815 (opens in a new tab)

#8536335
0x4f3948…ae2e97
0x39519639…6553b0
≈0.4614 WRBTC ≈2,198,044 SOV 0x1082b3e0…7b865d (opens in a new tab)

#8536347
0xb493b1…a2c155
0xa499ced3…f8d45a
≈0.317 WRBTC ≈1,510,060 SOV 0x6b7ddf65…8a8489 (opens in a new tab)

#8536354
0x50110e…f07962
0xbecb523d…83b474
≈0.305 WRBTC ≈1,452,809 SOV 0xc0c07f1a…c86074 (opens in a new tab)
Nine realized partial liquidations · 16 Aug 2026
UTC / blockLoanWRBTC repaidSOV seizedTransaction

#9155133
0xa499ced3…f8d45a ≈0.1065 ≈454,473 0x34fb3757…937f3a (opens in a new tab)

#9155138
0xbecb523d…83b474 ≈0.012 ≈51,401 0x0a09be12…bbb233 (opens in a new tab)

#9155151
0x39519639…6553b0 ≈0.009 ≈38,491 0x00b1c903…942ac6 (opens in a new tab)

#9155159
0x39519639…6553b0 ≈0.127 ≈544,045 0x79183dc6…54159f (opens in a new tab)

#9155187
0x39519639…6553b0 ≈0.05 ≈239,260 0x2036ecac…caae8a (opens in a new tab)

#9155488
0xa499ced3…f8d45a ≈0.02 ≈97,573 0xb9c886a0…d918d3 (opens in a new tab)

#9155501
0x39519639…6553b0 ≈0.01 ≈48,590 0x62e701a2…c5cb23 (opens in a new tab)

#9155516
0x39519639…6553b0 ≈0.01 ≈48,590 0x4732cf0e…f3cb66 (opens in a new tab)

#9155548
0xa499ced3…f8d45a ≈0.01 ≈48,786 0x4112e7d0…05d28b (opens in a new tab)
On-chain record

This happened before: the legacy 0x839c loan

Opened 3 February 2022 · expired 7 November 2024 · active and unsafe at the pinned 18 August 2026 snapshot

8D51 borrower opened the position in this transaction (opens in a new tab) , initially borrowing approximately 5.637 WRBTC. After collateral additions and 16 liquidations, the position still owed approximately 3.6666 WRBTC.

The same wallet was first funded by B7 in the uninterrupted setup sequence that included all four 2026 borrowers. In June 2022, later February borrower and former Exchequer multisig owner 4f39 · 0x4f3948…ae2e97 sent it approximately 385,915 SOV; within 4m57s, legacy 2022 borrower 8D51 · 0x8d5158…be0fb7 allocated the same underlying amount across three loan deposits. Exact values remain in the packet.

Exact SOV handoff (opens in a new tab) · First redeposit (opens in a new tab) · Second redeposit (opens in a new tab) · Third redeposit (opens in a new tab)

Current principal
≈3.6666 WRBTC
SOV collateral
≈613,652 SOV
Standalone AMM value
≈0.1107 WRBTC
Modeled shortfall
≈3.5559 WRBTC
Modeled coverage
≈3%

Dossier conclusion The same B7-linked operational cluster created material lender exposure years before the February 2026 session. Yago’s documented leadership, policy, response, and ratification roles place that exposure within his accountability record; custody and instruction records can allocate the executing key.

Direct source record

Yago dismissed the connection while leaving the transactions unchallenged

When the SOV-backed loan was raised, Yago answered, “No, of course not. What’s it got to do with me?” and said SOV owners could do what they chose. He later called the loan link baseless and characterized the broader exchange as “conspiratorial thinking” and “noise.” The preserved exchange contains no public commitment to require repayment, pause affected lending, pursue any available protective action, or investigate the identified positions.

Direct source record Community Call #73 · 01:06:37–01:07:58.700

Complete question and answer containing the baseless, conspiratorial, and noise response

Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked

Borrower-cluster value reached Sovryn’s USDt0 campaign signer

The loan record establishes the lender exposure. This separate trail follows where borrower value later reconverged: balances moved into February borrower and later RBTC hub b493 · 0xb493b1…a2c155 , that hub paid USDt0 campaign signer de169 · 0xde1690…5f6af2 current registered owner-address of the 0x924f Exchequer multisig, which also guards both Governors , and the campaign-signer wallet later sent the identified swap transaction and funded Sovryn’s USDt0 campaign.

Borrower-cluster value path to the USDt0 campaign signerFebruary borrower balances came back together in cluster hubs. The b493 hub sent zero point two three six RBTC to de169, a current owner of the operational 0x924f Exchequer multisig, which also guards both Sovryn Governor contracts. De169 later sent the transaction identified as the RBTC-to-USDt0 swap and signed a fourteen thousand four hundred sixteen point nine zero one USDt0 campaign transaction. An account displayed as FrenchVictory promoted the campaign three days later.FEB BORROWERSRBTC balancesreconverge in Juneb493 HUB0.236 RBTCde169 WALLETcurrent 0x924f ownercampaign signer2 tx · 7,117s14,417 USDt0Merkl campaign fundingDISPLAYED PROMOTIONFrenchVictory · 3 days laterAccount records should reconcile the swap output, source balance, and authorization.
Borrower-cluster value reached de169, a current owner of the operational 0x924f Exchequer multisig, which also guards both Sovryn Governor contracts. De169 then sent the transaction identified as the swap and funded the approximately 14,417-USDt0 Sovryn campaign. The swap output, account ledger, and authorization record are the next records needed to complete the accounting.
On-chain recordDossier conclusion
  1. Borrower balances came back together. On 18 June, February borrower 91AB · 0x91ab7f…021684 and February borrower 5011 · 0x50110e…f07962 moved nearly all of their 0.3943 and 0.4129 RBTC balances to February borrower and later RBTC hub b493 · 0xb493b1…a2c155 . February borrower 4f39 · 0x4f3948…ae2e97 sent 0.705 RBTC to a separate hub.
  2. Cluster hub to campaign signer. On 7 July, February borrower and later RBTC hub b493 · 0xb493b1…a2c155 sent 0.236 RBTC to USDt0 campaign signer de169 · 0xde1690…5f6af2 current registered owner-address of the 0x924f Exchequer multisig, which also guards both Governor contracts . Inspect the transfer (opens in a new tab) .
  3. Identified swap transaction and campaign funding. On 13 July, USDt0 campaign signer de169 · 0xde1690…5f6af2 sent approximately 0.234 RBTC in the transaction identified in the transaction audit as the RBTC-to-USDt0 swap. About two hours later the same wallet signed a Merkl reward-campaign transaction funding approximately 14,417 USDt0. Obtain the swap receipt/output and account ledger to complete the conversion accounting. Inspect the identified transaction (opens in a new tab) · inspect the campaign transaction (opens in a new tab) .
  4. Merkl’s campaign page connects the funding to Sovryn’s live product. The official opportunity page (opens in a new tab) names the protocol as Sovryn, the chain as Rootstock, a 50/50 RBTC/USDT0 liquidity position, and an approximately 14,000-USDt0 reward pool. Its Deposit action links directly to the Sovryn market-making dapp (opens in a new tab) . The displayed campaign runs from 16 July through 14 September 2026.
  5. Displayed promotion followed. Three days later, an account displayed as FrenchVictory announced a 10% APR USDt0/RBTC migration campaign to the Sovryn community.

Borrower-cluster value reached the USDt0 campaign-signer wallet at 0xde169…, a current registered owner-address of the operational 0x924f Exchequer multisig that also guards both Sovryn Governor contracts. That same wallet sent the transaction identified as the swap and funded the approximately 14,417-USDt0 Sovryn campaign. The swap output, account ledger, and campaign authorization are the next records needed to complete the accounting trail.

Supplied screenshot of a displayed FrenchVictory account announcing an incentivized USDt0 migration campaign offering a targeted 10 percent APR
Supplied exhibit VIS-07. The displayed post is dated 16 July 2026; the filename records capture on 17 August. SHA-256 9447bcb8…00dc28a. The supplied image contains no native platform metadata; the displayed date should be verified from the platform record.

What RBTC lenders stand to lose

Pool-wide shortfall estimate versus remaining-lender stressThe pool-wide collateral-sale estimate is a 13.8 percent shortfall across all lender claims. If early withdrawals exhaust cash and SOV loans recover zero, the lenders still waiting face a modeled 61.4 percent loss.POOL-WIDE SALE ESTIMATE86.2% recoveryBlock 9,162,594 · one combined SOV saleLATE-LENDER STRESS CASE38.6% recoverycash exhausted · zero SOV recoveryRedemptions are paid sequentially while pool cash remains.13.8% aggregate impairment · 61.4% remaining-lender cash-exhaustion stress.
Both calculations assume no borrower repayment, new capital, or outside liquidity under the conditions stated in the public packet. The packet provides the exact inputs and arithmetic.
Rootstock block 9,162,594 · 18 Aug 2026 17:41:35 UTC
MeasureRBTCMeaning
Total lender claims≈29.2089Canonical accounting claim balance at the block
Pool cash≈21.4134Immediately available before redemptions
SOV-backed principal≈4.7848All eleven active SOV-backed positions; all unsafe
Estimated recovery from the identified SOV/WRBTC exchange pool≈0.7408Estimated proceeds if all SOV collateral were sold through that one reserve pool at once
Estimated pool-wide shortfall≈4.044113.8% of lender claims, assuming no borrower repayment, new capital, or outside liquidity
Late-lender stress recovery≈3.0107Against approximately 7.7956 RBTC remaining after cash exhaustion

Outstanding lender exposure. The pool-wide collateral-sale estimate measures a 13.8% shortfall across all lender claims. A separate cash-exhaustion stress case measures a 61.4% loss for lenders left after earlier withdrawals consume the available RBTC, assuming zero SOV recovery and no repayment, new capital, insurance, or rescue. The located public record contains no committed cure.

Notice and response

Users warned leadership. Protection did not follow.

Victims supplied transaction hashes, balances, risk mechanics, and concrete requests. Leadership had the power to disclose, investigate, restore, pause, or support recovery. The public record shows no resulting protective commitment; liquidations and impairment followed.

Dossier conclusion

The notice record joins knowledge to consequence: exact warnings were delivered, the identified routes and loans remained unresolved, and linked voting defeated the executable FeeSharing recovery.

Inspect the complete notice, response, and recovery record
Direct source record

8–28 March

Treasury notices

On-chain recordDossier conclusionRecords authorities should compel

The RBTC route and total-asset warning

Warning delivered
Disclosures #1 and #3 published the route, balances, explorer links, and the separate November FastBTC flow.
Power to act
Leadership and Exchequer principals could publish the ledger, freeze further destinations, disclose the counterparty, and preserve signer records.
Recorded response
Yago called it overall treasury consolidation; Nahari invoked a third-party FastBTC liability.
Missing support
No transaction mapping or liability support was supplied; the November FastBTC flow and later 23.1464-RBTC route are distinct.
Protection not taken
No public exchange-account preservation, independent reconciliation, or complete current treasury statement followed.
Continuing harm
Victims lack a verified ledger and proceeds map; practical Exchequer liquidity remained impaired.
Intent inference
Organizational acknowledgment plus unsupported accounting after precise notice supports an inference of insider-directed execution.
Records to compel
Exchange customer-identification and account records, Exchequer instructions, FastBTC contracts, ledger, invoices, DD payees, and proceeds tracing.
On-chain record

March–April

Fee recovery

Direct source recordDossier conclusionRecords authorities should compel

An unopposed signal that expired, a defeated remedy, then ratification

Warning delivered
The SIP-0088 signal received approximately 50,211,182 votes for and zero against, but its recorded state was Expired; it was not executed.
Power to act
Exchequer could restore the previous FeeSharing code and transfer administrative control; leadership could support the proposals that would make those changes.
Recorded response
Five B7-first-funded wallets supplied every vote against both executable proposals.
What followed
The final recovery was blocked despite the earlier unopposed signal and later claim of Bitocracy legitimacy.
Protection not taken
The contract code that began withholding fees before the vote remained in place.
Continuing harm
The contract still omits listed-token revenue from the accounting entries that let stakers claim fees; the Exchequer multisig retains withdrawal authority.
Intent inference
Outcome-determinative linked voting followed by retrospective ratification supports deliberate preservation of the disputed change.
Records to compel
Stake custody, delegation history at vote snapshots, voting instructions, and internal SIP-0088/0089 communications.

Part III · Blocked recovery

Recovery was blocked—and the taking was ratified later

Five B7-first-funded wallets cast every vote against two executable recovery proposals. Later, B7-origin stake supplied 99.32% of the affirmative vote for Yago’s retrospective ratification through one operational voter address.

Proposal record: SIP-0085 was created on 6 December 2024. The non-executing SIP-0088 support vote was created on 5 March 2026; the two proposals that could restore the fee contract followed on 20 March. Yago published the SIP-0089 ratification proposal on 23 March; GovernorAdmin proposal 26 was created on-chain on 17 April. Exact contract names, proposal numbers, blocks, and times are in the public packet.

On-chain record

SIP-0088

Five B7-first-funded wallets supplied 100% of the approximately 62,572,734 votes against each paired executable recovery proposal—about 53.5% of all votes cast and enough to determine defeat.

Read the SIP-0088 forum record (opens in a new tab)

Direct source recordOn-chain record

SIP-0089

Yago sponsored retrospective ratification. One day before the proposal, two direct B7-first-funded addresses— A738 and 9369 —delegated their voting power to 0xfEE171…4a9e7e . That address is the FeeSharing deployment wallet named in Tyrone Johnson’s official deployment record, an Exchequer signer, and the SIP-0089 proposer-voter. At the vote snapshot, the two delegated weights summed exactly to the 31,574,812.5 votes it cast for ratification.

99.32%
99.32%B7-origin affirmative voting power
31,574,812.5 of 31,791,028.47 votes for
0.68%All other affirmative voting power
216,215.97 votes for, combined

What this establishes: B7-origin stake supplied 99.32% of the affirmative vote; every non-B7 source combined supplied 0.68%. The vote demonstrates near-total control of the ratification’s supporting weight through one operational voter address. Public records place Yago in sponsorship and leadership, while custody and instruction records remain necessary to allocate the private keys to specific natural persons.

A738 delegation (opens in a new tab) · 9369 delegation (opens in a new tab) · 31,574,812.5-vote transaction (opens in a new tab) · Yago’s forum proposal (opens in a new tab)

Dossier conclusion

The dossier concludes that governance was not a neutral check on the disputed conduct. B7-first-funded wallets supplied every vote against executable recovery, then B7-origin stake supplied 99.32% of the affirmative weight for ratification through one operational voter address after the withholding code was already live.

Intent finding

A connected pattern of control, execution, notice, and harm

Intent is inferred from the sequence and convergence of the documented acts.

Inspect the eight facts supporting the intent finding
  1. Advance controlRetained owner powers, concentrated signers, B7 funding, and threshold-capable Guardian paths existed before the disputed acts.
  2. Undisclosed executionUsable reserves were stolen through repeated transfers; code that stole staker revenue rights went live before a governance vote.
  3. Coordinated timingFour linked loans opened within 15m12s, hours before Yago’s reward announcement.
  4. Specific public noticeVictims supplied transactions, balances, risk mechanics, named requests, and a recovery proposal.
  5. Dismissal and unsupported accountResponses denied relevance, attacked the inquiry, or invoked a liability without ledger support.
  6. Ability to mitigateLeadership, Exchequer, and governance principals had practical routes to pause, repay, restore, disclose, and investigate.
  7. No recorded mitigation and concentrated votingNo recorded protective commitment followed; linked voting defeated the executable recovery.
  8. Measurable later harmLiquidations, unsafe positions, stolen staker fee rights, stolen usable treasury assets, and an unreconciled proceeds map remained.
Dossier conclusion

The combined warning, dismissal, absence of a recorded mitigation commitment, later liquidations, and impairment support the dossier’s inference of knowing disregard for lender harm. Integrated with the treasury and governance record, the dossier concludes that the course was intentional and insider-directed.

Responsibility

Who did what

Public records establish the policy, finance, and implementation roles. Key-custody and instruction records can allocate each private execution.

Dossier conclusion

The leadership-to-execution chain

  1. 1Yago announced, justified, and sought to ratify the policy. Sovryn called him project lead (opens in a new tab) . He designed the small Exchequer framework, proposed himself as a member, announced “what we have decided” (opens in a new tab) , said the decision came before Bitocracy ratification (opens in a new tab) , and described his later proposal as ratifying it (opens in a new tab) .
  2. 2Tyrone authored and committed the code and deployment record. That official record names 0xfEE171…4a9e7e as sender; the wallet then deployed the FeeSharing replacement and submitted the Exchequer multisig actions on-chain.
  3. 3Nahari occupied the finance lane. His records cover Exchequer participation, budgets, financial reporting, and the FastBTC treasury explanation.

The sequence joins policy, implementation, and finance; custody and communications remain necessary to allocate private execution.

Published role-wallet anchors: SIP-0041 published Exchequer Committee wallet Yago role wallet · 0x428a80…bdb2be · SIP-0041 published Exchequer Committee wallet linked in the Nahari record Armando role wallet · 0xa6df7b…63f4b7 · SIP-0047 published Contracts Guardian wallet Tyrone role wallet · 0x27ae0f…1346b7

Edan Yago speaker portrait
Direct source recordDossier conclusionRecords authorities should compel

Edan “Yago” Yago

Photograph source: Strategic Bitcoin Reserve Summit speaker profile (opens in a new tab)

Directly attributable
Project-lead role; authorship of the approved Exchequer framework; Exchequer participation; 17 February reward pause/redirection announcement; Call #72 consolidation explanation; Call #73 responses; executive-before-ratification account; and retrospective-ratification sponsorship.
Dossier conclusion
Yago was the leadership, policy, management, public-explanation, dismissal, and ratification principal for the disputed sequence.
Compel
Instructions, board/leadership communications, borrower-key allocation, exchange account records, and knowledge of the loan timing.
Elan Nahari 2025 speaker portrait
Direct source recordDossier conclusionRecords authorities should compel

Elan Nahari / “Armando Munoz”

Photograph source: Real-World Asset Summit 2025 speaker profile (opens in a new tab)

Public Sovryn identity
Nahari used “Armando Munoz,” shortened to “Armando” in project accounts and records.
Directly attributable
Co-founder and core-contributor roles; participation with Yago in the Exchequer’s executive treasury process; budget and financial-report work; first-person forum posts; and the Call #73 FastBTC account. At least eight linked files display elan@remake.money.
Dossier conclusion
The documentary chain places Nahari in Sovryn’s treasury accounting, reporting, budget, and explanation lane alongside Yago’s executive leadership.
Compel
Native account-authentication and custody records, report workpapers, general ledger, FastBTC agreements, signer instructions, and related-party records.
Direct source recordOn-chain recordDossier conclusionRecords authorities should compel

“Tyrone Johnson”

Public Sovryn identity
The pseudonym used in project, governance, source-code, and account records.
Documented role and actions
Publicly identified technical team lead; authored and merged the shutdown and withholding code; authored and committed the official mainnet deployment record whose artifact names FeeSharing deployment and Exchequer-submission wallet 0xfee171…4a9e7e · 0xfee171…4a9e7e named as sender in Tyrone Johnson’s official deployment record ; published role wallet later sent and signed a Guardian rotation; an account displayed as Tyrone supplied conversion and bridge wallet 8C · 0x8c9143…84f50b supplied by the displayed Tyrone project account during the on-chain-matched May 2024 session .
Dossier conclusion
The public Tyrone account is the documented technical and operational implementer or facilitator for core elements of the course.
Compel
Native Discord records, deployment logs, device/key custody, 8C continuity, DD signer identities, and the instruction chain for code and operations.

Combined responsibility finding: the transaction history establishes a centrally directed B7 operation. Yago, Nahari, and Tyrone occupy the documented leadership, accounting, and implementation chain around that conduct. Authorities should compel the custody, instruction, and communication records that assign the B7 funding wallet, borrower wallets, conversion and bridge wallet 8C, destination shared wallets DD, Exchequer multisig, and exchange actions within that chain.

The supplied 8C operational screenshots

These images show why 8C appears in the attribution record. They are displayed as context, while the transaction match—not the screenshot alone—carries the corroboration.

Supplied Discord screenshot in which a displayed Tyrone account says it is using a bridge interface and supplies the 8C wallet address
Supplied exhibit VIS-01. The displayed Tyrone project account supplies conversion and bridge wallet 8C · 0x8c9143…84f50b supplied by the displayed Tyrone project account during this on-chain-matched May 2024 session and describes the same bridge and negligible-balance retry pattern independently visible on-chain. SHA-256 e9628ae8…e6a3b63. The platform’s original export and account-access record should be preserved.
Open the two supporting Discord search views
Supplied wider Discord search screenshot showing additional results from the displayed Tyrone account
VIS-02. Wider account-search context · SHA-256 2e1fcd1e…6974b4.
Supplied Discord address-search screenshot showing two displayed references to the 8C wallet
VIS-03. Address-search context · SHA-256 49b94eeb…422544.

Part IV · Sovryn/BOS fund paths

Sovryn and BOS money used the same financial network

Public-chain records trace independently reconstructed BOS sale proceeds and Sovryn Exchequer assets through the same operations address, recurring-payment network, custody setup, and exact Bitcoin and Ethereum exchange routes. On Community Call #73, Yago acknowledged that BOS paid expenses for Sovryn and denied fund mingling nine and a half minutes later.

On-chain recordDossier conclusionRecords authorities should compel

On two networks, independently reconstructed funds converged at the same off-ramps

On Bitcoin, at least 20.01114355 BTC attributable to a high-confidence BOS Origins collector topology reached bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5 (opens in a new tab) . All three later Exchequer pegout routes delivered 23.13948498 BTC to that exact address.

On Ethereum, BOS sale funds used 0x509201… → 0xe1D4… → 0x5f65…. Exchequer-derived DD funds later reused the exact same forwarding proxy and terminal; another DD route used a sibling proxy from the same deployment family and reached the same terminal.

Candidate benchmark scale
$4,169,986.84 · 85.3% of Origins’ USD-valued counter at the matched daily-VWAP benchmark.
Exact convergence
One Bitcoin deposit address and one exact Ethereum proxy-to-terminal route were reused across independently reconstructed BOS and Exchequer sources.
Exchequer stablecoins reaching shared rails
At least 411,750.640097 nominal stablecoin units reached recurring recipients or the common Gemini-labeled endpoint.

Exact deposit-address reuse is materially stronger than a generic “same exchange” label. It supports a common credited-account, merchant, or off-ramp relationship that the exchange can identify.

Community Call #73 · two statements, 9m 30s apart

Yago said BOS paid Sovryn expenses—then denied fund mingling

At 35:03, Yago said some funds were paid by BOS on Sovryn’s behalf and needed to be consolidated at the end of 2025. At 44:33, the moderator asked whether Sovryn was mingling funds with BOS. Yago answered, “No.” Hear the denial in his own voice beside the earlier statement and the shared-route evidence.

Direct source recordCommunity Call #73 · 35:03

Yago says BOS paid funds on Sovryn’s behalf

Statement checked against the full call

“Some of those funds were paid out by BOS on behalf of Sovryn.”

He continued that those funds needed to be consolidated at the end of 2025 and said delaying consolidation let Sovryn maintain more liquidity in the protocol.

Hear the statement in the full Community Call #73 (opens in a new tab) · full source recording and captions checked

Direct source record Community Call #73 · 44:33–44:44

Asked whether Sovryn was mingling funds with BOS, Yago answers no

Excerpt checked against the full call

“No.”

Watch the full Community Call #73 on YouTube (opens in a new tab) · source recording and captions checked

The denial does not reconcile with Yago’s own cross-payment admission or the public-chain convergence. The missing records are the authorizations, separate ledger entries, project allocations, reimbursements, credited exchange accounts, and identities behind the shared wallets.

Follow every reconstructed collector, wallet, proxy, recipient, and exchange route
Direct source recordOn-chain recordDossier conclusionRecords authorities should compel

Multichain sale reconstruction

The candidate multichain benchmark reaches 85.3% of Origins’ sale counter

Origins records $4,888,380.30 in its USD-valued usdCollected field. Reconstructed stablecoin receipts and high-confidence Cardano and Bitcoin candidate paths produce a $3,974,628.13–$4,368,551.68 funding-day market benchmark. The daily-VWAP estimate is $4,169,986.84, or 85.3% of that counter.

Direct token paths

$432,623.93 in canonical stablecoins

The expanded reconstruction follows canonical stablecoin receipts on Ethereum, BNB Chain, Polygon, and associated collector branches. It includes the direct collector routes into 0x509201…AbD6 and labeled exchange infrastructure.

High-confidence Origins attribution

2,440,904.338471 ADA · about $1,873,923.65

Three Cardano pools contain 1,834 deposit UTXOs from 1,254 unique deposit addresses. Early pools routed to a Binance-labeled endpoint. The later controller placed an order using 277,394.921276 ADA and 36,652,194.91 BOS; the next transaction increased Minswap reserves by 277,392.171276 ADA and 36,652,194.91 BOS (opens in a new tab) .

High-confidence Origins attribution

20.01527801 BTC · about $1,863,439.26

The clean Bitcoin topology contains 297 one-output sweeps, 927 external input UTXOs, and 699 unique input addresses. Its collector rotation occurred within minutes of the independently reconstructed Cardano rotation before the balance moved to the later Exchequer deposit address.

Measurement basis: canonical stablecoins at face value and ADA/BTC receipts at matched Kraken daily low, VWAP, and high benchmarks. Bitcoin and Cardano are high-confidence Origins/Fireblocks attributions based on sale timing, unique-deposit sweep architecture, collector succession, and synchronized cross-chain rotations. Fireblocks documents the unique-address and sweep architecture (opens in a new tab) ; its vault map and the Origins order export can supply the first-party address assignment.

Central reconciliation difference: approximately $718,393.46. Accepted assets and vaults outside this reconstruction, order-time pricing, refunds, and platform accounting are the records needed to reconcile that difference.

On-chain recordDossier conclusionRecords authorities should compel

The BOS Bitcoin collector and stolen Exchequer BTC used one exact deposit address

bc1qccy9mn9h2ed6sjf7pvx7af6zc7zax0qaegadw5 (opens in a new tab)

High-confidence BOS Origins collector

The clean sale-window topology contains 20.01527801 BTC of external inputs. Conditional on that high-confidence Origins attribution, conservation assigns at least 20.01114355 BTC of the terminal deposits to sale-window value.

Collector A (opens in a new tab) rotated through a one-use intermediary into Collector B (opens in a new tab) , which later emptied its balance into the terminal above.

Independently traced Exchequer route

The Exchequer separately sent 23.1464 RBTC through three Rootstock-to-Bitcoin routes—worth $2.12 million when the transfers left. After bridge and transaction fees, 23.13948498 BTC arrived at that exact terminal. Inspect the three transaction-level receipts.

Nahari identified the destination as an exchange wallet and denied that it was OKX. OKLink labels it Gemini (opens in a new tab) . Public labels conflict downstream, so the address-assignment history, credited account, trades, withdrawals, and bank records are the decisive attribution record.

Significance: this is exact address reuse across two independently reconstructed sources—not merely use of the same exchange cluster. If the Gemini label is correct, Gemini’s deposit-address policy (opens in a new tab) and deposit workflow (opens in a new tab) make a common credited-account relationship the ordinary operational inference.

Direct source recordOn-chain recordDossier conclusionRecords authorities should compel

Shared custody and recurring payments

One custody and payment network served Sovryn treasury activity and BOS administration

DD received 508,947.877906 USDT reconciled to Exchequer-origin Rootstock assets. The matching DD Safes use the exact five-owner set installed on the official BOS token-owner and allocation Safes, and the same 8C address deployed both families. 0x509201…AbD6 and 0xcD9003…fBAA approved all 14 reviewed Ethereum DD executions.

Custody links

  • Deployment8C created DD and the official BOS Safe family
  • Shared owner setthe same five addresses control both Safe families
  • Observed quorum0x509201 and 0xcD900 approved every reviewed DD execution

Payment metrics

277,941 USDT
DD transfers outside the exchange routes
24 recipients
every address also paid by 0x509201
≥244,585.603045 USDT
strict Exchequer-derived minimum

Recorded transfers

  • BOS Exchequer0.02221978958 RBTC
  • Exchequer DDreconciled cross-chain assets
  • DD / 509 shared railsrecipients and exchange terminals

On-chain fact

All 24 DD recipients also appear in 0x509201’s genuine USDT payment history

Twenty-three were paid by 0x509201 before DD first paid them; the remaining address was paid later. Repeated recipient batches and exact amount matches establish that DD entered an existing 0x509201 recurring-payment network.

Collective lower bound

At least 411,750.640097 units reached payees or the common terminal

The bound charges every available unrelated DD unit and the full March route dilution against the Exchequer lot before attributing any remaining amount. It avoids adding overlapping subset bounds.

Controller attribution

Organizational roles are visible; most human key holders remain unresolved

Yago and Nahari are connected through documented management, finance, policy, and public-explanation roles. Tyrone is tied to 8C through the preserved supplied account record and on-chain-matched session. The public record identifies 0x509201 as a shared operations address; its natural-person controller remains unidentified.

  1. Separate funding described

    Yago said Sovryn had not funded BitcoinOS and that Sovryn’s treasury was not being requested.

  2. A large contribution path described

    He said Sovryn would need to invest or provide $5 million–$100 million in value or in-kind support (opens in a new tab) for its 10% BOS interest.

  3. Broad contributions authorized and acknowledged

    SIP-0083 (opens in a new tab) described substantial prior Sovryn contributions and further technical, audit, marketing, infrastructure, and network-operation support.

  4. Cross-payments acknowledged; mingling denied

    Yago said BOS had paid obligations on Sovryn’s behalf (opens in a new tab) , then answered “No” (opens in a new tab) when asked whether the projects were mingling funds.

Accounting and legal inquiry

Cross-project value transfer

Direct source recordOn-chain recordDossier conclusionRecords authorities should compel

Why the shared routes support an embezzlement and related-party-diversion inquiry

The public record now establishes more than shared personnel. Sovryn assets entered custody and payment infrastructure controlled by the same owner-address set used for official BOS administration; BOS collector-wallet funds and Exchequer-derived assets converged at exact exchange routes; and 0x509201 both received and approved payments from the shared DD Safe.

The Exchequer assets were liquid BTC, stablecoins, ETH, and BNB. Yago described Sovryn’s BitcoinOS interest as 10% of BOS supply. A token allocation has different liquidity, control, vesting, revenue, and economic rights from liquid treasury assets. Fair-value analysis requires the BOS allocation’s custody and vesting terms, its realizable value at each transfer date, BTC OS Limited’s cap table and revenue rights, and the consideration Sovryn received for every contribution.

Dossier conclusion: these facts support investigation of whether Sovryn property was diverted to BitcoinOS, related parties, or personal benefit without valid authority, fair consideration, complete disclosure, or reimbursement.

On-chain facts
Shared Safe owners, concentrated approvals, recurring payees, wallet-level pooling, and exact Bitcoin and Ethereum off-ramp reuse.
High-confidence Origins attribution
The Bitcoin and Cardano pool assignments are supported by sale timing, unique-deposit sweep topology, collector rotation, and cross-chain synchronization. Origins and Fireblocks hold the confirming vault map.
Purpose and beneficial ownership
Invoices, project codes, exchange KYC, trades, withdrawals, intercompany entries, and payee identities allocate what the transfers purchased and who received the economic benefit.
Embezzlement referral
Investigators should trace authority, accounting treatment, purchased work, reimbursement, and ultimate benefit—and identify whether any Sovryn property financed BitcoinOS or a related party without fair value returning to Sovryn investors.

Priority records: Origins/Fireblocks order and vault exports; Gemini and other exchange address-assignment, KYC, trade, withdrawal, and bank files; Sovryn and BTC OS Limited general ledgers and due-to/due-from accounts; DD/509 payee identities, invoices, payroll, and project codes; Exchequer budgets and approvals; BOS allocation valuation and custody; and private-key and instruction records for the shared owners.

Next: the sale claims and technical audit. The fund-flow record answers where reconstructed sale proceeds went and fixes the scale of the solicitation. Part V compares what BOS purchasers were told with the public bridge and code available while those funds were raised. Read the sale-claim audit.

Part V · BOS sale claims

BOS was sold with trustless-bridge claims while the public bridge was unfinished

Origins records 609,509,366.81 BOS sold and $4,888,380.30 in its USD-valued amount-collected counter. During that sale, official materials described trustless Bitcoin bridging without a multisig or federation. The public product was one-way and used valueless test assets; the reviewed public code implemented a two-party optimistic verifier and left the complete production bridge unfinished.

Dossier conclusionDirect source record

What the audit found

The reviewed public code implemented a two-party optimistic verifier; the advertised bridge additionally required custody, multiparty, two-way, recovery, and liquidity components. Think of BitSNARK less like a vault that automatically rejects a false withdrawal and more like a timed alarm-and-dispute system: an informed, funded watcher must detect a bad claim and complete the required Bitcoin challenge before the deadline.

Public artifact
The repository contained a two-party proof checker and dispute prototype. The marketed bridge required additional custody, multiparty, two-way, recovery, and liquidity systems.
Where trust remains
If no effective challenge completes, a false claim can reach the claimant path under the stated timeout and transaction conditions. Pre-signing adds a separate trust condition: a mandatory signer must never approve a hidden alternative, and after the allowed transactions are signed, at least one of the two required signing capabilities—and every copy or backup of it—must become permanently unusable. Bitcoin cannot verify either fact.
What was publicly available during the sale
The 16 February launch used valueless test assets and moved one way from Bitcoin Testnet 3 to EVM testnets. BitcoinOS described the return prover, two-way path, multiparty verification, and Grail code as future work while the sale used present-tense “trustless” claims.

The findings show a concrete gap between categorical no-counterparty marketing and the conditional public design. That substantiation gap warrants investigation into whether sale-linked descriptions gave purchasers a misleading or incomplete impression.

Direct source record

What purchasers were told

On 29 January 2025 (opens in a new tab) , Edan Yago said BTC could move across chains trustlessly “without having to use a multisig or a federation.” A 19 February paid promotion (opens in a new tab) quoted him saying users could experience “truly trustless Bitcoin bridging.”

The 27 February sale page (opens in a new tab) said BitcoinOS enabled any blockchain to connect with Bitcoin trustlessly and placed that representation beside BOS purchases and possible annual revenue flows above $7 billion. The 3 March sale notice (opens in a new tab) repeated the trustless claim with a purchase call to action, escalating stages, bonuses, referrals, and a $50 minimum.

Direct source record

What was publicly available during the sale

The 16 February launch record (opens in a new tab) described valueless test assets, a one-way Bitcoin Testnet 3-to-EVM path, and a return prover and two-way bridge still being built. The reviewed repository described a local two-party regtest demo while multiparty verification, two-way operation, and Grail code remained future work.

Origins’ two completed backend periods record the full launchpad sale. The first completed period (opens in a new tab) and its post-maintenance continuation (opens in a new tab) record 609,509,366.81 BOS in tokensSold and $4,888,380.30 in the USD-valued usdCollected counter across accepted crypto assets. The first period includes the issuer’s $2.225 million Phase 1 result (opens in a new tab) ; the displayed total is the sum of the two completed periods.

Measurement: first-party Origins API counters. Audited net proceeds and the composition of purchased, bonus, referral, and staker allocations require issuer, banking, and subscription records. The sale-total record preserves both periods, exact decimals, response snapshots, scope, and exclusions.

The sale claims, in Edan Yago’s and Gadi Guy’s own words

Hear the representations before inspecting the technical record beneath them. The recordings establish what was said; the code, symbolic model, signature rules, and bounded lab record establish what the public system could substantiate.

Direct source record BitcoinOS at Bitcoin Nashville · 1:24–1:32

Yago says Bitcoin can have “truly trustless” layer twos

Excerpt checked against the full source recording

“It allows Bitcoin to have truly trustless layer twos—rollups where any type of functionality can occur.”

Watch the full BitcoinOS presentation on YouTube (opens in a new tab) · source recording and captions checked

Direct source record BitcoinOS at Swiss Web3 Fest · 9:05–9:12

Yago presents Grail as cross-chain BTC without a multisig or federation

Excerpt checked against the full source recording

“take BTC and move it across chains trustless, without having to use a multisig or a federation.”

Watch the full BitcoinOS keynote on YouTube (opens in a new tab) · source recording and captions checked

Direct source record Bitcoin Magazine NL interview with Gadi Guy (publisher title spells his surname “Ghai”) · 7:20–7:44

Guy says BitSNARK enables trustless bridges without counterparty risk or a person or group able to steal funds

Excerpt checked against the full source recording

“There is no person or—or group of persons who together can steal your money.”

Watch the full Bitcoin Magazine NL interview on YouTube (opens in a new tab) · source recording and captions checked

Later acknowledgments: in April, Guy said Grail still needed productionization (opens in a new tab) . In June, Yago acknowledged additional trust assumptions (opens in a new tab) . Those statements confirm conditions omitted from the categorical sale language.

Inspect the detailed BOS sale-wallet and cross-project control record
Direct source recordOn-chain recordDossier conclusionRecords authorities should compel

Sale proceeds · wallet reconstruction

Detailed Ethereum BOS collector and downstream-route record

Origins’ unique-deposit-address model (opens in a new tab) left a repeatable on-chain fingerprint. Exact buyer payment, deposit-address sweep, common gas funding, published stage price, collector succession, and official vesting-beneficiary matches identify three rotating primary Ethereum collectors with high confidence. The same method also identifies a smaller associated branch at 0x60c507….

How the wallets were identified

A sale gas wallet activated isolated deposit addresses with 0.001 ETH. Each address received a participant’s canonical token and swept the identical raw amount into a collector. The early gas wallet funded the middle gas wallet (opens in a new tab) and the later multichain gas wallet (opens in a new tab) ; the middle wallet also funded the later one (opens in a new tab) . This links all three primary collector generations independently of address labels. The 60c branch adds five exact payment-and-sweep pairs through four new deposit addresses. (opens in a new tab) The full reconstruction contains 144 exact purchase sweeps across 127 participant deposit addresses; forty-three payment-source addresses also appear as beneficiaries in the official Community Sale vesting record. These are discovered lower bounds because Origins permitted exchange deposits and separate payment and claim wallets.

  1. 01 · Early BOS Ethereum collector

    0xBb55bB…243243
    Exact sweeps
    79
    Deposit addresses
    68
    Payer = beneficiary
    22

    3 Mar 2025–12 May 2025. Gas funder 0x528D59cA…d6753a.

  2. 02 · Middle BOS Ethereum collector

    0xFeD3a5…fF0628
    Exact sweeps
    27
    Deposit addresses
    26
    Payer = beneficiary
    8

    13 May 2025–30 Jun 2025. Gas funder 0x8bb0d983…e23c7a.

  3. 03 · Post-maintenance multichain BOS collector

    0x1160A7…abf08C
    Exact sweeps
    33
    Deposit addresses
    29
    Payer = beneficiary
    14

    10 Jul 2025–22 Oct 2025. Gas funder 0x64f842e5…c2afa3.

Other verified chains: the same 1160 collector also received participant-specific deposits on Arbitrum (opens in a new tab) —about 3,841 ARB and 0.191 ETH—and Polygon (opens in a new tab) —about 1,335 USDT and 389 POL. The Arbitrum balance moved to one unlabeled address; the reviewed Polygon record establishes receipt but no onward destination. Exact values remain in the wallet-flow record.

Early collector · exchange endpoint

About $102,167 in canonical stablecoins, plus WBTC and ETH, reached Binance 14

BB55 moved pooled balances through 0x6C250D…6038. That relay sent 102167.018527 USDT/USDC/DAI units, 0.00274432 WBTC, and 27.157479067347059439 ETH into the publicly labeled Binance 14 address. Inspect the route. (opens in a new tab) The credited customer account is identifiable from Binance and Fireblocks records.

Middle collector · project operations

Middle-period assets reached both an operational wallet and 0x509201 directly

FeD3 sent 43585.792331 USDT/USDC units and 5.799965340728752 ETH to 0x4ad662…D4a. That wallet was first funded by 0x509201…AbD6 (opens in a new tab) and later sent 23,000 USDT and 5,000 USDC (opens in a new tab) back. FeD3 also sent 4937.393862 canonical stablecoin units, 0.001 WBTC, and 1.196003859314349906 ETH directly to 0x509201 (opens in a new tab) . It and 1160 later reused the early Binance relay (opens in a new tab) . The pooled 4ad account requires its internal ledger to assign each payment after receipt.

Post-maintenance collector · direct 0x509201 route

About $234,160 in stablecoins and 3.6055 ETH went directly to the shared operations address

On 14 November 2025, 1160 sent 204103.50752 USDT (opens in a new tab) , 30056.588245 USDC (opens in a new tab) , and 3.605528140408725578 ETH (opens in a new tab) to 0x509201…AbD6 . That address already links B7, Sovryn’s official Ethereum bridge, DD, and the official BOS Safe family.

TGE and vesting record

The official Community Sale vault created 1,162 cancellable schedules

The Ethereum vault (opens in a new tab) created schedules for 1,141 beneficiaries totaling 351,227,296.06 BOS. That equals 57.62% of Origins’ tokensSold counter. The remaining 258,282,070.75 BOS requires reconciliation across late wallet submissions, other distribution paths, cancellations, bonuses, and the complete order ledger.

Administrative power

The same BOS owner Safe holds forfeiture and salvage authority

Every decoded schedule is cancellable. An emergency cancellation of two schedules (opens in a new tab) moved 496,028.63 BOS of unclaimed vested and unvested principal to the official BOS owner Safe, which forwarded the same amount to the original vault deployer in the same batch. That owner Safe uses the five-address control set shared with DD.

Records needed to finish the proceeds map

Authorities should obtain the Origins and Fireblocks deposit-address map and audit log; the full order, bonus, referral, refund, claim, and vesting ledger; Binance, Gemini, Kraken, and Coinbase credited-account, trade, and withdrawal records; beneficial-controller and key-custody records for every collector and destination; and the Sovryn and BTC OS Limited intercompany ledgers, invoices, reimbursements, payroll, vendors, and complete source-and-use accounting.

Inspect the machine-readable wallet-flow record · run its verifier · inspect the 0x509201 follow-through record.

Investor diligence

Cross-project control risk

Direct source recordOn-chain recordDossier conclusionRecords authorities should compel

Detailed BitcoinOS operational and bridge-control risk record

BitcoinOS identifies Edan Yago as co-founder and CEO and Elan Nahari as co-founder and COO (opens in a new tab) . The 2025 BTC OS Limited MiCA filing (opens in a new tab) lists Yaron Edan Yago as the only named management-body member and says the company issues and supports BOS and coordinates contributors. On-chain records identify part of the shared infrastructure: the DD wallets that received Sovryn treasury-derived assets have the same five-owner set and 8C deployer as the official BOS token-owner and allocation Safes. The same two addresses repeatedly operated DD and appear throughout the BOS Safe family. Inspect the cross-project custody record above. The natural persons behind those owner addresses and the allocation of DD’s payments between projects remain unidentified.

Protective judgment: until those controls are published and independently verified, users should not entrust BTC to a BitcoinOS bridge or treat “trustless” as an operational fact or a reason to buy BOS. Test claims with valueless assets; do not substitute founder reputation or operator count for verifiable control separation.

Documented Sovryn conduct and harm
This dossier characterizes the treasury transfers and the taking of stakers’ fee rights as theft. It documents Yago as the leader who announced and defended the policy, dismissed the lender warning, and sponsored its ratification; it places Nahari in an Exchequer finance, accounting, and reporting lane. It also documents five B7-first-funded wallets casting every vote against two executable recovery proposals, 99.32% B7-origin support for later ratification, liquidations, and lender exposure. The located record contains no leadership commitment to require repayment, pause affected lending, pursue any available protective action, or independently investigate the loans after users disclosed the danger. This is the dossier’s evidence-based theft finding; authorities and courts determine criminal charges and liability.
Why borrowing against SOV matters
Borrowing RBTC against thinly traded SOV obtained bitcoin liquidity without an immediate market sale and transferred collateral-liquidity risk to the lending pool. At the measured snapshot, selling all eleven loans’ SOV collateral through the only identified pool under the stated assumptions left an estimated 4.0441-RBTC shortfall. The pattern warrants examination as an exit-risk scenario: it converted SOV exposure into RBTC liquidity while leaving lenders with residual collateral-liquidity risk. The B7-linked borrower cluster remains pseudonymous; authorities should compel key-custody and communications records to identify its controllers and motive.
The protective test for “trustless”
A bridge is meaningfully independent of leadership only if users’ BTC remains safe and redeemable when any founder, company officer, software publisher, operator, or custodian becomes dishonest, compromised, or unavailable. Reputation is not a security control. Independent beneficial control must be verified through ownership, key-custody, infrastructure, and instruction records; counts of addresses, keys, or operators are insufficient.
Sale-period BitSNARK control surfaces
The reviewed design depended on a capable watcher completing a funded challenge before timeout, correct setup and transaction graphs, no unauthorized alternative being signed during setup, both required script-path signing capabilities not remaining jointly available, and the discrete log for the configured Taproot internal key remaining unavailable. Under the stated premises, an invalid claim can reach the claimant path if no effective challenge confirms; if both required script-path signing capabilities survive, their holders can co-sign a fresh alternative spend through the locked-funds leaf. BitcoinOS should produce the key-generation, erasure, custody, backup, and instruction records that identify who held each capability and whether every disallowed path became unavailable.
Later Grail Pro control surfaces
BitcoinOS’s later architecture (opens in a new tab) uses TEE-held operator keys, mutable rosters and thresholds, and a documented 12-of-16 example. Twelve effective authorities can authorize a release; five refusals or outages leave only eleven and block the normal path. The page’s statement that twelve compromises are required for “loss of service or funds” is therefore wrong for service availability: 16 − 5 = 11 < 12. A mandatory custodian policy (opens in a new tab) can give that custodian a veto over its BTC. “Twelve authorities” is a threshold count; independence requires separate beneficial controllers, infrastructure, update paths, and recovery powers.
Frontend and software-publisher risk
BitcoinOS’s own trust model says users trust the frontend (opens in a new tab) , which queries operator keys to generate Taproot deposit addresses. Its operator instructions use the mutable image tag grailpro/cosigner:latest (opens in a new tab) , not a pinned digest. A substituted roster or address could send a deposit outside the intended quorum. The tag can change what a later pull resolves to; if operators deploy it and the admission policy accepts it, one shared faulty or malicious release could affect nominally separate operators. The reviewed record leaves the referenced frontend audit, expected enclave measurement, immutable image digest, update approver, release history, allowlist, attestation log, and controller unidentified.
Company-level access and loss terms
A pinned public Grail frontend source file (opens in a new tab) contains terms that call BTC OS Limited the “Bridge Operator,” say reverse redemption is supported only where technically feasible, warn of partial or total loss, and reserve company discretion to suspend or restrict access. BitcoinOS should produce the versioned deployment, presentation, acceptance, custody, and service-access records that establish when those terms operated and who exercised the reserved authority.
Records still needed
Before anyone relies on “trustless” or “decentralized,” BitcoinOS should publish the production operator and custodian roster; legal and beneficial-controller mapping; vault addresses and scripts; key-generation and erasure evidence; internal-key custody; challenger funding and data plans; roster, threshold, software, emergency, and recovery authority; reproducible source and build hashes; TEE measurements and approval logs; independent audits; incident history; and BOS source-and-use-of-funds accounting.
Inspect the full technical proof and claim chronology
Technical terms, translated
Zero-knowledge proof
A cryptographic proof of a statement defined by a circuit, verification key, and public inputs. Bitcoin custody and release require separate mechanisms.
Optimistic verification
The complete proof is checked outside Bitcoin. Bitcoin adjudicates a disputed computation only when someone challenges in time.
One-of-N honesty
Safety depends on at least one watcher having the correct data, funds, and time to complete every required challenge transaction before the deadline. Being honest is not enough if the challenge is never confirmed.
Pre-signing and key erasure
Participants sign the allowed future transactions before funds are locked. “Erasure is a premise” means security assumes no hidden alternative was signed and that enough signing power—and every copy or backup needed to restore it—then became permanently unusable. Bitcoin can verify the signatures, but not either off-chain fact.
Safety versus liveness
Safety asks whether an invalid claim can release funds. Liveness asks whether an honest user can complete a withdrawal.
TEE
A protected hardware environment—documented for later Grail Pro as AWS Nitro—relied on to run approved code and protect keys.

The counterexamples and their premises

A universal security claim fails when one permitted adverse execution exists. BitcoinOS’s own transitions and script supply the protocol premises; a separate valueless Core lab run tests only the analogous threshold-signature principle.

Counterexample 01Invalid proof + no timely challenge

The published symbolic model lets ProofUncontested consume Locked Funds without consulting IsProofValid. An audit patch specializes the model’s fixed CHOOSE expression to false and adds a strong label-preservation invariant. TLA+ TLC returned this three-state symbolic trace:

  1. InitLocked funds exist.
  2. ProofThe prover publishes an invalid asserted result.
  3. ProofUncontestedThe locked-funds label disappears into the prover path.

Result and premises: TLC proves symbolic reachability in this abstract model. Applying that trace to Bitcoin requires a matured timelock, unspent inputs, an available valid presignature, no effective challenge, and confirmation of ProofUncontested; CSV time, signatures, value, ownership, recipients, and Bitcoin consensus sit outside the model.

Counterexample 02Both signing capabilities survive

The intended locked-funds Tapscript leaf checks one prover signature and one verifier signature. It contains no proof predicate or opcode-level output covenant. Its acceptance condition reduces to:

Accept(T) = Verify(pkP, sigP, T) ∧ Verify(pkV, sigV, T)

Taproot SIGHASH_DEFAULT binds the transaction outputs, so old signatures cannot simply be copied to a changed recipient. But if both signing capabilities survive—or both parties pre-sign that exact alternative before erasure—they can authorize it. The finite coalition model finds 1 authorizing coalition out of 4, with a minimum of 2 capabilities.

Result and premises: the intended script leaf permits the two holders to authorize a fresh spend if both signing capabilities survive. The whole P2TR output also has a configurable internal-key path. Safety therefore relies on a correct finite graph, output-binding signatures, an unavailable internal-key discrete logarithm, and effective deletion or non-retention of at least one of the two required script-path signing capabilities.

Core lab analoguePre-signing works—but Bitcoin cannot verify key deletion

An isolated Bitcoin Core v31.1 regtest used P2WSH/ECDSA, legacy OP_CHECKMULTISIG, and SIGHASH_ALL. It accepted and mined a prescribed two-of-two spend. Copying the signatures onto a changed recipient failed; freshly signing that alternative with both retained keys succeeded; one signature failed.

Original recipient + both signaturesAccepted and mined
Changed recipient + copied signaturesRejected
Changed recipient + both retained keysAccepted
Original recipient + one signatureRejected

Lab scope: the experiment establishes the output-binding and retained-key proposition in a generic P2WSH/ECDSA analogue. Exact BitSNARK P2TR/Tapscript/Schnorr replay remains unreproduced, and the public packet lacks a deterministic replay fixture. Bitcoin verifies signatures and transactions, not erasure. A public, independently audited setup and custody record can provide evidence of deletion; it cannot rule out a hidden copy or secretly pre-signed alternative.

Verified capabilities in the public code

The reproduced public result was an optimistic verifier prototype. The bridge marketed to purchasers also required custody, networking, redemption, recovery, and liquidity systems.

Direct source record

Reproduced successfully

  • v0.1: 56 of 56 public tests passed.
  • v0.2: TypeScript compiled; 154 tests passed and two were skipped.
  • The separate decoder test verified its supplied Groth16 witness.
  • The public code implements a real two-party optimistic dispute prototype.
Dossier conclusion

Capabilities absent from the reproduced results

  • The only Circom statement in the reviewed v0.2 tree was a fixed multiplier test, not dynamic bridge inclusion, burn, amount, or recipient data.
  • The repository contained no executable two-way Grail custody, mint/burn, redemption, operator, recovery, or liquidity system.
  • A Jest end-to-end test was skipped, while a separate Docker-dependent local two-party regtest demo remains unreproduced; this audit therefore contains no reproduced networked multiparty two-way bridge result.
  • Any private prototype sits outside the reviewed public tree and requires production source, build, audit, and deployment evidence for assessment.

Later Grail Pro documentation confirms a different conditional trust model

Grail Pro is a later architecture, separate from the sale-period design. Its first-party documentation shows a production-facing system dependent on institutional operators, protected hardware, and threshold authorization—not ZK alone.

Direct source record

The documented 12-of-16 example

BitcoinOS’s architecture (opens in a new tab) says operators verify proofs in AWS Nitro enclaves and authorize Bitcoin releases through a threshold. A dated article (opens in a new tab) gives twelve signatures out of sixteen as its example.

Minimum effective signing coalition
12 of 16
Authorizing subsets, including supersets
2,517
Minimum refusals that block the normal threshold path
5
If a distinct custodian is also mandatory
13 minimum; custodian alone can veto
If the custodian is one of the 16
12 including it; custodian alone can veto

Deployment scope: custodian membership remains ambiguous, so both cases are shown. Authority counts and human counts are distinct: enclave isolation could require separate compromises, while common build, attestation, roster, cloud, recovery, or implementation control could affect many. The minimum human coalition remains indeterminate until BitcoinOS publishes the topology, beneficial-control map, and reproducible Grail Pro code. These figures count logical coalitions rather than probabilities.

An expert warned Yago months before the sale

On 24 July 2024, Weikeng Chen challenged whether the announced mainnet result supported the covenant and bridge claims being made and urged Yago to scrutinize what his technical team had told him. The later audit confirms the core concern: the public record showed a proof-verification milestone, not a completed public two-way trustless bridge.

Direct source recordDossier conclusion

What Chen warned about—and what the code shows

  • The warning: after a participant linked the BitcoinOS announcement, Edan Yago said BitcoinOS had done it on mainnet (opens in a new tab) . Chen challenged the covenant claim (opens in a new tab) and urged Yago to scrutinize the technical team’s representations (opens in a new tab) .
  • The audit’s central finding: the identified transaction supports a real proof-verification milestone, but the reviewed public code was a two-party optimistic verifier—not a completed, public, two-way bridge that removed counterparty trust. Its safety depended on a timely challenger, correct setup, a complete pre-signed transaction graph, no complete signing coalition remaining available, no secretly pre-signed alternative, and an unavailable Taproot internal-key discrete logarithm.
  • The later audit: Chen challenged the mainnet covenant claim and warned Yago to scrutinize his technical team’s representations. The audit found the same substantive gap: the public artifact was a two-party optimistic verifier whose safety depended on off-chain setup, key deletion, and active challenge—not the completed trustless bridge later marketed beside the BOS sale.
  • Relevance to the BOS sale: trust, setup, challenge, and implementation scope were disputed publicly months before categorical bridge statements were used to promote BOS. The thread establishes contemporaneous notice; the code audit independently establishes the substantiation gap.

Method: Telegram supplies the dated warning and Yago’s response. Pinned source code, executable tests, an audit-patched symbolic TLA+ trace, finite coalition arithmetic, Bitcoin’s signature rules, and the bounded Core lab record supply the technical conclusion independently.

BitVM Builders Telegram screenshot showing Weikeng Chen challenging Edan Yago’s claim about covenants on Bitcoin mainnet without OP_CAT
VIS-05 · 24 July 2024. BitVM Builders covenant challenge · SHA-256 6730ea2e…219ac6.
BitVM Builders Telegram screenshot showing Weikeng Chen warning Edan Yago about the claims attributed to the BitcoinOS technical team
VIS-06 · 24 July 2024. BitVM Builders technical-warning exchange · SHA-256 c6f38239…ea32.

Preservation boundary: the public message pages corroborate the displayed sequence, authors, UTC dates, and reply chain. A native Telegram Desktop export would still be the strongest record for deleted, edited, service, or media content.

Claims, verified capability, and BOS sale chronology
DatePublic representation or eventVerified technical or sale record
23–24 Jul 2024 BitcoinOS reported a BitSNARK mainnet demonstration (opens in a new tab) ; Yago called it done on mainnet; Chen publicly challenged the implementation and claim scopeThe identified transaction and decoder establish a proof-verification milestone. A complete dispute graph and public two-way bridge remain unreconstructed, and the design adds active-challenger and setup assumptions
29 Jan 2025Yago promoted moving BTC across chains without a multisig or federationThe pinned v0.1 baseline placed networked multiparty operation and a two-way peg in future work
16–19 Feb 2025 One-way valueless testnet (opens in a new tab) followed by a paid promotion for “truly trustless” bridgingThe product record still described a return prover, two-way bridging, and mainnet delivery as future work
26–27 Feb 2025A repository snapshot carries 26 February Git metadata; the direct presale page (opens in a new tab) followed on 27 FebruaryThe snapshot described a local two-party regtest demo and future multi-verifier/two-way work; public availability on 26 February requires hosting or release evidence
3 Mar 2025 The BOS sale opened (opens in a new tab) with categorical trustless-bridge language and a direct purchase call to actionThe public bridge remained unfinished and one-way on valueless test assets
20 Mar 2025 “Fully production-ready” attributed to Yago (opens in a new tab) The same-day issuer post (opens in a new tab) described a basic two-party regtest release and future multiparty/Grail work; exact scope remains unresolved
14–24 Apr 2025Guy said no person or group could steal funds; BitcoinOS reported $2.225 million raised in phase one (opens in a new tab) The same interview said Grail still needed productionization; purchaser-level exposure and reliance require account, communication, and allocation records
Jun–Sep 2025 Yago acknowledged additional trust assumptions (opens in a new tab) The MiCA paper (opens in a new tab) called Grail trust-minimised and planned a further audit before production
3 Mar–22 Oct 2025Two completed, contiguous Origins backend periods (opens in a new tab) covered the full launchpad sale$4,888,380.30 in the USD-valued usdCollected counter and 609,509,366.81 BOS in tokensSold; the Phase 1 report falls within the first period
Dossier conclusion

Established findings

  • Technical conditions: rejecting an invalid claim requires an effective challenge to complete in time. Constraining spends to the approved graph separately requires that no unauthorized transaction was pre-signed, the two script-path capabilities do not remain jointly available, and the Taproot internal-key discrete logarithm remains unavailable.
  • Substantiation gap: categorical bridge claims accompanied a sale while the public product was one-way/testnet and public two-way, networked, multiparty bridge components remained unfinished.
  • Fundraising measurement: Origins supplies first-party platform counters across two completed periods. Audited net receipts and the allocation breakdown require issuer, banking, and subscription records.
Records authorities should compel

Records authorities should compel

  • Archived marketing, terms, disclosures, and code versions delivered to each purchaser
  • Marketing approvals, technical reviews, and communications showing what each speaker knew and intended
  • Dated private code, builds, audits, and deployment records claimed to support each sale-period statement
  • Purchaser exposure, deposits, allocations, token disposition, reliance, causation, and loss records
  • Corporate attribution, agency, jurisdiction, and records required for a final legal finding

Conclusion: taken together, the dated sale claims, public implementation limits, first-party fundraising counters, and reconstructed proceeds routes support focused investigation into what purchasers were told and how their payments were controlled and used. Audited net receipts, knowledge, reliance, causation, and loss require the private records identified above. Read the full proof, dated claim matrix, sale-total record, wallet-flow record, and 0x509201 follow-through record.

Transition to recovery: the record now joins the sale claims, the system’s technical conditions, the reconstructed money paths, and the full Origins counter. Part VI identifies the purchaser, platform, code, key-custody, exchange, and accounting records needed for attribution and recovery.

Part VI · Recovery

Preserve evidence. Trace the money. Pursue recovery.

This record is built for action. Victims can document losses, reporters can verify the central claims, and investigators can preserve platform and exchange records before they disappear.

For victims

Preserve the statements and promises you relied on, along with wallet exports. Calculate deposits, withdrawals, rewards, and remaining exposure. Record the steps you took to limit harm, and submit only copies through the encrypted intake. Never submit a seed phrase, private key, or password.

Submit evidence securely

For reporters

Start with the concise media brief, chronology, transaction set, statement-versus-record exhibits, reproducible datasets, and source index. Ask named principals for document-backed answers to the compulsory-record requests.

Read the media brief Download the full evidence packet

For authorities

Preserve exchange, platform, BitcoinOS marketing, code, bridge-control, and BOS purchaser records immediately; identify the people controlling the five shared DD/BOS owner addresses and the borrower keys; obtain the missing Sovryn/BTC OS Limited intercompany ledgers, DD payee file, and FastBTC file; trace centralized-exchange and related-party proceeds; and interview the named policy, accounting, and implementation principals.

Review records to preserve and obtain

Records authorities should preserve and obtain

Records authorities should compel
  • Immediate preservation of forum, Discord, GitHub, Google Drive, email, device, and cloud audit logs
  • Natural-person and beneficial-controller identity, key custody, devices, backups, and signer logs for the 0x924f Exchequer multisig, Contracts Guardian shared wallet, B7, borrower wallets, 8C, D9, and all five shared DD/BOS owner addresses
  • Centralized-exchange customer-identification and complete account activity for the exchange-style Bitcoin deposit and consolidation route
  • Sovryn and BTC OS Limited board, leadership, committee, budget, invoice, payroll, vendor, general-ledger, journal-entry, intercompany-account, reimbursement, cost-allocation, bank, exchange, and tax records
  • FastBTC lender/provider contracts, liabilities, approvals, wallets, and payment mapping
  • FeeSharing tickets, code-review messages, deployment logs, instructions, and vote planning
  • Borrower communications, custody logs, repayment discussions, risk review, and liquidation response
  • BitcoinOS bridge-key, operator, custodian, roster, threshold, software-allowlist, code, build, audit, deployment, incident, and recovery records
  • Origins and Fireblocks deposit-address, vault, sweep, workspace, API-user, policy, signer, and audit logs; Binance records for the identified relay account and later withdrawals
  • BOS purchaser exposure, deposits, allocations, token disposition, reliance, causation, loss, related-party, fundraising, and source/use-of-funds records
  • DD recipient identities, invoices, payroll and vendor purpose, project allocation, approvals, beneficial ownership, current custody, and subsequent asset disposition
  • Victim reliance, deposits, stakes, lending claims, withdrawals, rewards, cost basis, and damages
Appendices A–C · publication record Inspect the full record Open the chronology, call evidence, source index, exhibit index, and publication status.

Record files

Open the reproducible datasets and publication materials directly, or continue into the complete appendices below.

Appendix A

Case chronology

A compact sequence for referrals and reporting. Each current-state number remains tied to its own block.

to
On-chain record

A shared wallet requiring two of three owner approvals sent 5.9 RBTC to common funding wallet B7

The transfers identify the shared wallet that funded B7 and the approving wallet addresses. Obtain account, signer, device, and instruction records to identify the people behind those approvals.

On-chain recordDossier conclusion

B7 funded a rapid setup batch of linked wallets

Ten newly used wallets sent their first outgoing transaction directly back to B7 73–380 seconds after B7 funded them. The timing and common destination establish a centrally directed setup session.

On-chain record

The Exchequer multisig held both FeeSharing administrative powers

The power to replace the FeeSharing code and the power to operate it remained with the Exchequer multisig at 0x924f. No later transfer of either power to a Bitocracy-controlled delayed-execution contract was found in the contract history.

On-chain record

Legacy borrower wallet 8D51, first funded through B7, opened the SOV-backed RBTC loan

After later collateral additions and 16 liquidations, this earlier loan remained active, unsafe, and deeply undercollateralized at the pinned August 2026 snapshot. It shows that the linked lending pattern began four years before the February 2026 loans.

to
On-chain recordDossier conclusion

February borrower wallet 4f39 transferred exactly 385,915 SOV to legacy borrower wallet 8D51, which put the full amount into three loans

The exact amount moved from the later February borrower to the legacy borrower and into the loans within 4 minutes 57 seconds, directly linking their operations.

Direct source recordOn-chain record

A project Discord account displayed as Tyrone supplied the address of conversion-and-bridge wallet 8C during a live bridge session

Same-day public BOB transactions match the address, tokens, small test amounts, failure and retry, and final transfers shown in the conversation. Obtain the native Discord account and message records to authenticate the account and preserve the full exchange.

to
Direct source record

Yago publicly described BitcoinOS as separately funded and said Sovryn had not funded its development

Yago wrote that Sovryn had not funded BitcoinOS, called the developer team self-funded, described separate contributors and funding, and said Sovryn's treasury was not being requested. He repeated the current-funding distinction on Community Call 63.

Direct source record

Yago described the value and fundraising contribution contemplated for Sovryn's 10% BOS allocation

Yago said that, for Sovryn to receive 10%, it would need to invest between $5 million and $100 million in value or provide in-kind value to that degree; he also said Sovryn was expected to engage actively in raising BOS funds. This is a contemporaneous qualification to the June separation statements.

to
Direct source record

Official Sovryn records acknowledged substantial BitcoinOS contributions and continuing investment

SIP-0083 said Sovryn had contributed incubation, design, research, development, testing, communications, and community engagement throughout BitcoinOS development and committed further technical, audit, interface, marketing, infrastructure, and network-operation resources. Yago then called Sovryn a significant BitcoinOS participant.

to
Direct source recordDossier conclusion

The completed BOS launchpad sale recorded about $4.89 million in Origins' USD-valued amount-collected counter

Origins' two contiguous completed backend periods record 609,509,366.81050959 BOS in tokensSold and $4,888,380.29942801134947357397 in the USD-valued usdCollected field across accepted crypto assets. Public-chain reconstruction identifies non-overlapping stablecoin roots plus high-confidence Bitcoin and Cardano collection candidates. Stablecoin face value and transaction-date Kraken daily VWAP for 20.0153 BTC and 2,440,904.338471 ADA produce a $4,169,986.839549 scale benchmark, or 85.3% of the counter. This is not Origins order-time accounting or an audited net-proceeds figure; complete order, rate, refund, allocation, exchange, banking, and Fireblocks records remain required.

to
On-chain recordDossier conclusionRecords authorities should compel

High-confidence Bitcoin and Cardano Origins candidates rotated collectors in synchronized batches

Seven Cardano consolidation batches and the Bitcoin collector-A consolidation occurred within 16–23 minutes on 12 May. On 13 May, the main Cardano and Bitcoin rollovers landed at successor collectors 5 minutes 15 seconds apart, and their residual transfers followed 6 minutes 48 seconds apart. Sale timing, unique-deposit topology, official BOS-recipient crossmatches on Cardano, and this independent timing fingerprint support common Origins infrastructure attribution; they do not identify a natural-person controller.

to
On-chain recordDossier conclusionRecords authorities should compel

The candidate BOS Bitcoin collector deposited into the terminal later used by the Exchequer route

Eight deposits totaling 20.0975 BTC reached one exact terminal address. Conservation through the candidate collection pool establishes a 20.0111-BTC sale-window lower bound, or 20.0109 BTC after excluding both test transfers. The Origins or Fireblocks vault-to-address inventory is needed to make the candidate mapping first-party-confirmed.

to
On-chain recordDossier conclusion

Long-running Sovryn operations key 0x509201…AbD6 provisioned three later DD/BOS owner keys

The key first-funded 0x5C07…96C2, 0xe31c…67C6, and 0x59c4…ed0F with consecutive Ethereum nonces inside four minutes. The following day 8C used those addresses in the five-owner set for the official BOS token-owner and allocation Safes.

On-chain recordDossier conclusion

8C deployed the official BOS token-owner and allocation Safe family with one five-key control set

The token-owner Safe and the allocation Safes used the exact five owner addresses later installed on DD. Net initial allocation balances reconcile BitcoinOS's published 32% ecosystem and 35% founding-entity buckets.

to
On-chain recordDossier conclusionRecords authorities should compel

The fully reconciled third Cardano sale collector funded the official BOS distributor

The collector sent 8,000 ADA through a relay that forwarded 7,998.83 ADA to the official BOS Cardano distributor. The same collector's exact root, fee, and outflow ledger reconciles to zero; the public chain establishes this use but not its internal accounting category or authorization.

Direct source record

The BOS token began live trading

Address 8C created the cross-chain DD shared wallets 15 days later, and Exchequer multisig asset movements began 36 days later. Obtain Sovryn/BitcoinOS allocation, proceeds, and related-party records for this period.

On-chain record

8C created the DD shared wallet on BNB Chain, requiring two of five owner approvals

The same address created a matching Ethereum shared wallet 63 seconds later with the same five owners and two-signature requirement.

On-chain recordDossier conclusion

8C created the matching DD shared wallet on Ethereum

The Ethereum and BNB Chain DD shared wallets had the same owner list and two-signature requirement, later received assets routed from the Exchequer multisig, and reused the exact five-owner set from the official BOS token-owner and allocation Safe family. The same two keys approved all 14 observed Ethereum DD executions.

to
On-chain recordDossier conclusion

Two reconstructed BOS sale collectors transferred stablecoins, WBTC, and ETH directly to 0x509201…AbD6

Collector 0x1160…f08C sent 204,104 USDT, 30,057 USDC, and 3.606 ETH. Middle collector FeD3 sent 2,798 USDT, 2,024 USDC, 0.001 WBTC, and 1.196 ETH in the same consolidation window. Their sale function is established by exact participant-deposit sweeps, linked gas infrastructure, official vesting-beneficiary matches, cutover timing, collector succession, and published stage-price corroboration. The recipient address already links B7, Sovryn's official Ethereum bridge, DD, and the official BOS Safe family.

to
On-chain recordDossier conclusionRecords authorities should compel

0x509201 sent 200,000 USDT into a Gemini forwarding route that deposited the exact amount at Gemini 4

Before the BOS collector receipts, 0x509201 held only 49,536 USDT. With no material intervening USDT inflow, balance conservation establishes that at least 150,463.919739 of the 200,000-USDT Gemini deposit came from the designated collector lot. The bounded minimum entering first-hop routes that terminate at publicly labeled Gemini, Kraken, and Coinbase addresses is 183,441.682473; after route losses and relay prebalances, at least 183,433.939419 necessarily reached those labeled exchange endpoints.

On-chain recordDossier conclusionRecords authorities should compel

The same BOS collector sent swept participant RBTC into Sovryn's Exchequer multisig

Eleven participant-specific Rootstock deposit addresses swept 0.0222 RBTC into 0x1160…f08C, and every identified payer matched a later Community Sale vesting beneficiary. The collector then sent 0.0222 RBTC, net of onward transaction gas, into Sovryn's 0x924f… Exchequer. This is a direct BOS-presale-proceeds route into Sovryn's treasury and requires intercompany source-and-use reconciliation.

On-chain recordDossier conclusion

The Exchequer multisig held about $3.20 million of gross on-chain assets

At Rootstock block 8,265,000, a realized-output method valued non-SOV holdings at about $2.663 million and 5.07 million SOV at about $536,947 using Sovryn's on-chain reference price. A separate same-time price check reached $3.250 million. These figures value gross assets before unidentified liabilities or off-chain accounts.

to
On-chain record

Twenty-seven material Exchequer multisig operations moved treasury assets

The non-double-counted ledger records 24 primary exits and three final BNB bridge executions. Three executions sent 23.1464 RBTC out of the Exchequer, worth an estimated $2,122,679.92 in total using the one-minute Coinbase BTC-USD candle close containing each execution. The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e approved all 27. Tyrone's official deployment record later names this same wallet as its sender. Only four of the eight historical Exchequer owner addresses approved any operation in this set.

to
On-chain recordDossier conclusionRecords authorities should compel

All three Exchequer-derived Bitcoin releases reached the exact earlier BOS-candidate terminal

After Rootstock-to-Bitcoin bridge and Bitcoin fees, three releases delivered 23.1395 BTC into the exact address previously used by the high-confidence BOS Bitcoin candidate. OKLink labels the terminal Gemini, while BitInfoCharts labels a recurring downstream consolidator OKEx. The address reuse is exact; venue, credited customer, beneficial owner, purpose, trades, withdrawals, and fiat proceeds require private records.

to
On-chain recordDossier conclusionRecords authorities should compel

Cardano sale infrastructure and mint-derived BOS funded a Minswap BOS/ADA liquidity position

The third Cardano collector sent 277,396.064793 ADA to a purpose-created controller. A mint-derived reserve sent 36,670,452 BOS to the same address. The controller placed 277,394.921276 ADA and 36,652,194.91 BOS into an order that increased the Minswap V2 pool reserves by 277,392.171276 ADA and 36,652,194.91 BOS. All 30,314,501,400,595 returned LP units remained in an unspent controller output at the research cutoff; the controller's human identity and authorization remain unresolved.

to
On-chain recordDossier conclusion

Treasury-linked DLLR was converted to ZUSD and redeemed through Zero against borrower collateral

Five Exchequer transfers sent 569,214 DLLR to conversion wallet 8C. That wallet made five matching DLLR-to-ZUSD calls and eleven successful Zero redeemCollateral calls before five follow-on transfers returned 6.2281 RBTC to the Exchequer. Zero redemptions reduce borrower debt but also remove the oracle-priced RBTC equivalent, forcing a reduction in Bitcoin collateral exposure at the redeemer's chosen time. Because 8C held commingled balances and the successful calls exceeded the identified treasury DLLR input, not every redeemed unit or returned satoshi can be assigned solely to the Exchequer funds.

Direct source record

Sovryn's official X account told readers to stake SOV for BTC and USD income

The post said, “Stake SOV right now to earn up to 21.37% APR BTC and USD.” The preserved official embed response and screenshot record the solicitation and its timestamp.

to
On-chain record

Wallets staked SOV and lengthened existing locks during the promotion-to-notice period

Fifteen addresses directly added 111,068 SOV in 24 transactions. Twenty addresses lengthened locks on 9,962,956 SOV in 27 transactions. Individual victim files can join these transactions to dated evidence of promotion exposure, purchase and staking decisions, and loss.

to
On-chain recordDossier conclusionRecords authorities should compel

DD sent Exchequer-attributed funds through the exact BOS-linked Ethereum forwarding route

DD sent 100,000 USDT to the same e1d4 proxy used after BOS collector receipts; the proxy forwarded the exact amount to the publicly labeled Gemini 4 gateway. The January route's standalone Exchequer-origin lower bound is 66,645 USDT. Exchange records are required to identify the credited customer, trades, withdrawals, and beneficial owner.

to
Direct source recordOn-chain record

Tyrone-authored code shut down principal fee claims on live Rootstock mainnet

The FeeSharing deployment/submission wallet and Exchequer signer at 0xfEE171…4a9e7e deployed the code and submitted the request to the Exchequer multisig, and enough Exchequer owners approved it. Tyrone's official deployment record names this wallet as its sender. The live shutdown lasted 44 hours 20 minutes and began before the larger 29 January BTC decline. Yago later cited the recent BTC decline when justifying the February change that stole staker fee rights.

Direct source record

Archived staking-page HTML records a Webflow Last Published timestamp

The preserved HTML begins with Webflow metadata dated after the January claim shutdown and before Yago's 17 February notice. Webflow revision, approval, and account logs should identify the exact page version and approvers behind that publication event.

to
On-chain record

Seven B7-funded wallets withdrew 10,048,901 SOV from staking

The withdrawals occurred in 1 hour 52 minutes 24 seconds. Four of those seven wallets then opened the February loans.

to
On-chain record

Four linked wallets opened SOV-backed RBTC loans within 15 minutes 12 seconds

The loans paid a total of 1.465 RBTC from the lender pool to the borrower wallets and added risk from selling illiquid SOV collateral in a liquidation.

Direct source record

Yago announced the RBTC and ZUSD payout pause and the revenue change this dossier identifies as theft

The announcement came 12 hours 35 minutes after the last linked loan opened. It said the change would follow the next payout; the Exchequer multisig still held the contract powers needed to carry it out.

Direct source recordOn-chain record

The FeeSharing deployment/submission wallet at 0xfEE171…4a9e7e submitted the 100%-withholding change

A Tyrone-authored deployment commit identifies 0xfEE171…4a9e7e as the sender. That wallet deployed the replacement code and submitted the Exchequer multisig upgrade, RBTC withholding, and ZUSD withholding actions within 3 minutes 16 seconds.

to
On-chain record

The Exchequer multisig activated 100% withholding for RBTC and ZUSD

Enough Exchequer owners approved the replacement code, and the 0xfEE171…4a9e7e deployment wallet executed both token additions. Staker claim entries for these fees stopped before any Bitocracy vote.

On-chain record

Six linked wallets staked 6,986,587 SOV within 43 minutes 16 seconds

Three wallets that had not borrowed restaked their exact withdrawn amounts. Nearly all stakes used the same 16 February 2029 lock target.

Direct source record

Public Disclosure #2 warned that the linked loans threatened RBTC lenders

The notice identified all four loan transactions, asked Yago and Nahari to close the loans, and requested safer SOV-collateral rules.

On-chain record

B7-funded voting power defeated the SIP-0088 recovery proposals

Five B7-first-funded wallets cast all 62,572,733.758251524367271838 votes against the executable proposals to reverse the fee change and transfer FeeSharing control to Bitocracy.

Direct source record

Yago sponsored a proposal to ratify the already executed staking-revenue theft

SIP-0089 was expressly presented as approval and formalization after the operational decision and contract change had already occurred.

Direct source recordDossier conclusionRecords authorities should compel

Yago acknowledged BOS-on-behalf-of-Sovryn payments and then denied fund mingling

At 35:03 on Community Call 73, Yago said BOS had paid some funds on Sovryn's behalf and that they needed year-end consolidation. At 44:42, asked whether Sovryn was mingling funds with BOS, he answered 'No.' The DD/BOS shared-control and payment record requires the intercompany ledger, payment mapping, invoices, approvals, and reconciliation supporting both statements.

to
On-chain recordDossier conclusionRecords authorities should compel

DD funds passed through 0x509201 and a sibling forwarding proxy to the same Ethereum terminal

DD sent 120,000 USDT to 0x509201, which exchanged that amount through Curve for 119,923 USDC and then sent 122,000 USDC through sibling proxy f6c8 to the same 5f65 terminal, drawing on a pre-existing USDC balance for the difference. Allocating DD's maximum other funds only once across the January and March routes and deducting maximum March dilution establishes a joint 133,809.640217-unit Exchequer-origin lower bound at the terminal. Across all DD outflows, at least 411,750.640097 nominal stablecoin units reached either that terminal or recurring recipient wallets. These are gross-arrival lower bounds, not unique dollars or proof of purpose.

to
On-chain recordDirect source recordDossier conclusion

Borrower-cluster value reached the wallet that later funded a Sovryn USDt0 campaign

February borrower and later hub B493 sent 0.236 RBTC to campaign signer de169, a registered owner-address of the 0x924f Exchequer multisig, which remains the current guardian of both Governor contracts. De169 later sent the transaction identified in the transaction audit as an RBTC-to-USDt0 swap and signed the 14,417-USDt0 Merkl campaign transaction. Merkl's official opportunity page identifies Sovryn as the protocol, Rootstock as the chain, an approximately 14,000-USDt0 reward pool, and a Deposit link to Sovryn's market-making dapp. Obtain the swap receipt, full account ledger, campaign authorization, and signer records to complete the source-of-funds accounting.

On-chain record

Nine liquidation events struck three February loans

Liquidators repaid 0.3545 WRBTC and seized 1,571,209 SOV. All four February positions remained active and unsafe at the following audit snapshot.

On-chain recordDossier conclusion

The pinned lender-pool snapshot showed all 11 active SOV-backed loans unsafe

At Rootstock block 9,162,594, selling all SOV collateral through the on-chain exchange pool produced a modeled 4.0441-RBTC lender shortfall.

Direct source record

Sovryn's live staking page continued to advertise BTC rewards and SOV purchases

The official page displayed “up to 20% APR,” “Rewards in BTC,” “Payouts in BTC,” and a “Buy SOV” button months after the 100% RBTC and ZUSD withholding action. The page HTML, screenshots, capture time, and hashes are preserved.

Appendix B

Call evidence ledger

All nine excerpts were checked against the complete calls. Their captions, continuous time ranges, visual treatment, source links, and file fingerprints are recorded with each player.

Direct source record Community Call #72 · 00:43:38–00:46:27

Complete question and answer on the treasury reaction, BTC exposure, and replenishment

Source and caption check
Complete
Visual treatment
Audience chat retained; unrelated attendee roster masked.
Source SHA-256
19a58e343052b7fa4cf1bc2ffbd2cc4a6f07b5df85404596339c4bcaa2469ac3
MP4 SHA-256
4b441866be709c148e5af4e9d6563512bfec6fcfd9413e6fa8f6b1649cda9a02
WebM SHA-256
48ff52362a5ba0f70553f079e20e0a44c0c80ebb7b36e84e36270f8854ac261a
Captions SHA-256
df212b4a4a1c88b45cf7c53d2dc38214c32b6c138cd42de0f5d921cc3a07a5a0
Direct source record Community Call #72 · 00:46:27–00:47:58

Complete question and answer describing overall treasury consolidation

Source and caption check
Complete
Visual treatment
Audience chat retained; unrelated attendee roster masked.
Source SHA-256
19a58e343052b7fa4cf1bc2ffbd2cc4a6f07b5df85404596339c4bcaa2469ac3
MP4 SHA-256
bcc8f3f6e16ff869545c74acbd0b8b8d02e2a8f4ae742325d1c14f487dc96466
WebM SHA-256
b475eeaa2c8a3e06246b2786702a63e14cff80a79af674f30f2fae0b55dfd97f
Captions SHA-256
5b6ae303d8dad71dfa47a6cd140eb5d7cd9cc10f9e29be9ecfc693e304f61cca
Direct source record Community Call #73 · 00:42:54–00:43:40

Yago responds when the founding-member loan is raised

Excerpt checked against the full call

“No, of course not. What’s it got to do with me? Or the conversation that we’re having? Like, people who own SOV can do with it whatever they choose.”
Source and caption check
Complete
Visual treatment
Audience chat retained; unrelated attendee roster masked.
Source SHA-256
b3bd2fa7df6ad132ecfa7fdca336c2f6903886a4fa2106468c157a54801081d6
MP4 SHA-256
08f5912794c9cedea7c0c2d3a17b88876264c3d26a4849d1fef6b82e4bf3eab0
WebM SHA-256
a59caf30c431b62d9c9224874eae8bd50e49c797b6081145d9487b6218ed5b2e
Captions SHA-256
98f68df13598ab8269ce32f9d42b30791c2f295ac18f9ec9d2f93e8959627f60
Direct source record Community Call #73 · 44:33–44:44

Asked whether Sovryn was mingling funds with BOS, Yago answers no

Excerpt checked against the full call

“No.”
Source and caption check
Complete
Visual treatment
Audience chat retained; unrelated attendee roster masked.
Source SHA-256
b3bd2fa7df6ad132ecfa7fdca336c2f6903886a4fa2106468c157a54801081d6
MP4 SHA-256
b6d301b49d35f1d547ffc5c9dc66de8f32d05dc83c99b20cd4ef58b4c31eaf32
WebM SHA-256
21cfea6b5fa3ad4bddf0eaa95091b386085ae90998f12a745e0e6946d71899d6
Captions SHA-256
386a2947fcaf5d621a2cc67e4181d179a1435245a794075a5b1fe1abd065de71
Direct source record Community Call #73 · 00:51:07–00:54:18

Complete question and answer containing the general third-party FastBTC explanation

Source and caption check
Complete
Visual treatment
Audience chat retained; unrelated attendee roster masked.
Source SHA-256
b3bd2fa7df6ad132ecfa7fdca336c2f6903886a4fa2106468c157a54801081d6
MP4 SHA-256
bfdc30bdcd9ede41245b0fbcdc3a38238936f03055ff8d8d7cfdb3ade3be345f
WebM SHA-256
9f3cd511e6fa0bb10a2541f92f31b5d65b597678e1e4627a9bce435df78a71fc
Captions SHA-256
fb95c271b9d6e7d8c74d51411e44719db1eac6fd375c6dc14623ee3002b68a19
Direct source record Community Call #73 · 00:57:38–00:58:41

Follow-up states the duty to protect RBTC lenders from illiquid collateral

Source and caption check
Complete
Visual treatment
Audience chat retained; unrelated attendee roster masked.
Source SHA-256
b3bd2fa7df6ad132ecfa7fdca336c2f6903886a4fa2106468c157a54801081d6
MP4 SHA-256
b98bfcdcae25eaf85ab04cdb12ba29d65308f6c37af35944be87d5a86c58ecaa
WebM SHA-256
e54d67bd96b81736911fc88986630b3961b8e1fe1907455313a94e4c1d7f30f9
Captions SHA-256
cae5d44041e35240fcfff1804273ef6095885d2b46e21d88b564285516da9b79
Direct source record Community Call #73 · 01:00:32–01:02:10.900

Complete question and answer containing the inability to explain the precise redemption method

Source and caption check
Complete
Visual treatment
Audience chat retained; unrelated attendee roster masked.
Source SHA-256
b3bd2fa7df6ad132ecfa7fdca336c2f6903886a4fa2106468c157a54801081d6
MP4 SHA-256
d537d349bb9f0cbae4c95a4fbd81e8a5100fe5e375b9f6915a775fde1e03373d
WebM SHA-256
84f2542468b2e5e57b9d35dcdac03d0d698fbd0f4fcde8fba8c832cf6cf8117d
Captions SHA-256
8c153198646281755f33ce798420a506bb4b16797bf424a763eb2dadedd5dd12
Direct source record Community Call #73 · 01:06:37–01:07:58.700

Complete question and answer containing the baseless, conspiratorial, and noise response

Source and caption check
Complete
Visual treatment
Audience chat retained; unrelated attendee roster masked.
Source SHA-256
b3bd2fa7df6ad132ecfa7fdca336c2f6903886a4fa2106468c157a54801081d6
MP4 SHA-256
248fa82c6febd5f21fdda4b197b86b1c79b399fc0b3b854bf24776dfe8ca7842
WebM SHA-256
01ca6c37fea48f8f6330360a6c9484217b922f94e5cd71965bd31e43df28de43
Captions SHA-256
f42958e6ccb09a1aa57bd8ef2caf2e8561a155e9eab780bde69030107aac8f05
Direct source record Community Call #73 · 01:08:46–01:11:33.400

Complete question and answer containing the bad-faith, lack-of-understanding, and no-deep-mystery response

Source and caption check
Complete
Visual treatment
Audience chat retained; unrelated attendee roster masked.
Source SHA-256
b3bd2fa7df6ad132ecfa7fdca336c2f6903886a4fa2106468c157a54801081d6
MP4 SHA-256
82defdf3491874d887d870b4c3fdd041f4359b9860b9b8292c91ae24698047c4
WebM SHA-256
2d89c18dd0bc56c4ce0b3ea119fd6540a6f40b4dc58a78b67c45e12ade4d0246
Captions SHA-256
afb830f4bc0540ae274854a1ed30b3a641e2092ec5fed7d3af442842fd743cf9

Appendix C

Primary records and exhibits

Public links let readers inspect each source and rerun the calculations. The evidence packet preserves the datasets and methods; restricted originals and private submissions remain outside the public site.

Exhibit index

Public source index

Release checklist

Publication record

The public release was published only after the narrative, media, captions, hashes, redactions, evidence packet, and recovery materials passed the recorded release checklist.