<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Intel on Cryptos &#8211; Haveno-based DEX for private P2P-exchanges without KYC</title>
	<atom:link href="https://www.dawnswap.finance/category/intel-on-cryptos/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dawnswap.finance</link>
	<description>One of the last resorts to achieve privacy, even anonymity in trading cryptos against fiat</description>
	<lastBuildDate>Wed, 29 Jul 2026 08:57:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://www.dawnswap.finance/wp-content/uploads/2025/11/cropped-dawnswap_1_logo-32x32.webp</url>
	<title>Intel on Cryptos &#8211; Haveno-based DEX for private P2P-exchanges without KYC</title>
	<link>https://www.dawnswap.finance</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>10 Questions to Ask Your Blockchain Analytics Provider about Data Quality</title>
		<link>https://www.dawnswap.finance/2026/07/29/10-questions-to-ask-your-blockchain-analytics-provider-about-data-quality/</link>
					<comments>https://www.dawnswap.finance/2026/07/29/10-questions-to-ask-your-blockchain-analytics-provider-about-data-quality/#respond</comments>
		
		<dc:creator><![CDATA[dexadm]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 06:50:04 +0000</pubDate>
				<category><![CDATA[Intel on Cryptos]]></category>
		<category><![CDATA[analytics]]></category>
		<category><![CDATA[blockchain]]></category>
		<category><![CDATA[chainalysis]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[provider]]></category>
		<guid isPermaLink="false">https://www.dawnswap.finance/?p=52</guid>

					<description><![CDATA[Blockchain analytics tools provide critical intelligence to compliance teams, regulators, and investigators. These professionals use that intelligence to uncover illicit activity, prioritize investigations, support enforcement actions, and ultimately hold bad actors accountable. But those outcomes depend on one thing: the quality of the underlying blockchain data. If the data is wrong, investigators will waste time &#8230; <a href="https://www.dawnswap.finance/2026/07/29/10-questions-to-ask-your-blockchain-analytics-provider-about-data-quality/" class="more-link">Continue reading <span class="screen-reader-text">10 Questions to Ask Your Blockchain Analytics Provider about Data Quality</span></a>]]></description>
										<content:encoded><![CDATA[<p>Blockchain analytics tools provide critical intelligence to compliance teams, regulators, and investigators. These professionals use that intelligence to uncover illicit activity, prioritize investigations, support enforcement actions, and ultimately hold bad actors accountable. But those outcomes depend on one thing: the quality of the underlying blockchain data.</p>
<p>If the data is wrong, investigators will waste time and resources chasing a false lead, and compliance analysts could miss sanctions exposure. The downstream effects can be even worse: a single incorrect attribution can discredit hundreds of related insights, undermine entire investigations and lead to wrongful customer terminations.</p>
<p>Selecting the right blockchain analytics provider is therefore a mission-critical decision. Evaluating the quality of the underlying data requires more than comparing feature lists or coverage claims. Any provider performing rigorous analytical work should be able to explain the methodology behind its conclusions, the evidence supporting them, the safeguards used to prioritize accuracy, and show that the claims hold up under scrutiny and independent testing. The following questions are designed to assess the rigor, transparency, and evidentiary standards behind a provider’s methodology as part of your due diligence.</p>
<h2 id="how-addresses-get-grouped">How addresses get grouped</h2>
<ol>
<li><b>How do you determine that multiple addresses belong to the same entity? </b></li>
</ol>
<p>Some methodologies establish common ownership deterministically. Others infer ownership  probabilistically. Both approaches can be useful, but it is important to understand which method is being used and when.</p>
<ol start="2">
<li><b>What happens when your grouping methods get it wrong? </b></li>
</ol>
<p>Every technique has blind spots. For example, CoinJoin transactions need to be identified and excluded from UTXO co-spending heuristics. A good provider has mapped out these edge cases and built protections against them, and not just assumed errors are rare.</p>
<ol start="3">
<li><b>Do you use different techniques for different blockchains? </b></li>
</ol>
<p>Different blockchains, like Bitcoin and Ethereum, operate in fundamentally different ways with distinct architectures, transaction models, and behavioral patterns. As a result, the techniques used to group addresses together should differ as well. If a provider uses the same general terminology across blockchains, ask what methodology is being applied.</p>
<h2 id="how-entities-get-labeled">How entities get labeled</h2>
<ol start="4">
<li><b>What evidence supports your labels, and how reliable is it? </b></li>
</ol>
<p>A label confirmed by a reliable source — for example a dataset seized by law enforcement — is very different from one based on a single uncorroborated report, e.g an anonymous tip.</p>
<ol start="5">
<li><b>If you changed the label, would the address grouping still hold up? </b></li>
</ol>
<p>The grouping and the label should be independent. If removing a label causes the grouping to fall apart, neither claim stands on its own.</p>
<ol start="6">
<li><b>Do you distinguish between who runs a wallet and who uses it? </b></li>
</ol>
<p>When you deposit crypto at an exchange, your deposit address is linked to you, but the exchange controls it. Failing to distinguish between users and service providers can lead to incorrect ownership claims and attribution errors. A provider should be able to explain how it differentiates between who uses an address and who ultimately controls it. The same challenge exists with nested entities, where one company relies on another company’s custodial or wallet infrastructure. Robust attribution requires understanding not just who interacts with an address, but who ultimately controls it.</p>
<h3 id="how-methodology-gets-tested">How methodology gets tested</h3>
<ol start="7">
<li><b>Has your methodology been challenged in court? </b></li>
</ol>
<p>Legal proceedings test whether the methodology behind clustering and attribution can be submitted as evidence. A methodology that has satisfied the Daubert standard is fundamentally different from one that has never faced it, even if they seem similar on the surface. If a provider’s methods are relied upon in investigations, compliance decisions, or enforcement actions, understanding how those methods have performed under legal scrutiny can provide valuable insight into their rigor, methodology, and reliability.</p>
<ol start="8">
<li><b>Have you participated in independent accuracy studies? </b></li>
</ol>
<p>Opportunities to verify the accuracy of blockchain analytics are rare and valuable. But if law enforcement seizes wallet infrastructure, then outside parties can compare empirical evidence with attribution data. These moments provide a unique opportunity to validate whether a provider’s methodologies produce accurate results in the real world. Has your provider welcomed that kind of external testing, or avoided it?</p>
<ol start="9">
<li><b>Where do you draw the line with machine learning? </b></li>
</ol>
<p>ML is great for spotting patterns. But if ML outputs automatically get treated as confirmed facts, errors can quickly multiply. Understanding where a provider relies on machine learning can help you distinguish between evidence-based conclusions and probabilistic assessments that may require further validation. Ask how your provider leverages ML and if those outputs are not grouped with other methodologies and are clearly labelled as such.</p>
<ol start="10">
<li><b>Can you explain how any given cluster was built? </b></li>
</ol>
<p>For any specific cluster, a provider should be able to walk you through how it was constructed and what evidence supports it. If they can’t trace how a cluster came together, then their cluster might not be right.</p>
<p>Any blockchain analytics company should be able to provide clear and specific answers to these questions. They’re the product of transparency, quality control, and strong evidentiary standards — the same standards your investigations depend on.</p>
<p>To learn more about Chainalysis’s data standards, read <a href="https://www.chainalysis.com/reports/defining-the-cluster/" target="_blank" rel="noopener">Defining the Cluster</a>, our formal ontology for blockchain address analysis and intelligence claims, and <a href="https://www.chainalysis.com/blog/ontology-data-quality-blockchain-analytics/" target="_blank" rel="noopener">why we published it</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dawnswap.finance/2026/07/29/10-questions-to-ask-your-blockchain-analytics-provider-about-data-quality/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>An Ontology for Accountability: Defining What Data Quality Means in Blockchain Analytics</title>
		<link>https://www.dawnswap.finance/2026/07/29/an-ontology-for-accountability-defining-what-data-quality-means-in-blockchain-analytics/</link>
					<comments>https://www.dawnswap.finance/2026/07/29/an-ontology-for-accountability-defining-what-data-quality-means-in-blockchain-analytics/#respond</comments>
		
		<dc:creator><![CDATA[dexadm]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 06:47:16 +0000</pubDate>
				<category><![CDATA[Intel on Cryptos]]></category>
		<category><![CDATA[chainalysis]]></category>
		<category><![CDATA[data]]></category>
		<guid isPermaLink="false">https://www.dawnswap.finance/?p=50</guid>

					<description><![CDATA[We built this to be questioned Before I came to blockchain analytics, I spent years in academia studying the formal correctness of distributed systems. My work was proving, mathematically, that code and protocols behave correctly under every possible execution variant. Not most of them. All of them. In that world, there isn’t a “good enough.” &#8230; <a href="https://www.dawnswap.finance/2026/07/29/an-ontology-for-accountability-defining-what-data-quality-means-in-blockchain-analytics/" class="more-link">Continue reading <span class="screen-reader-text">An Ontology for Accountability: Defining What Data Quality Means in Blockchain Analytics</span></a>]]></description>
										<content:encoded><![CDATA[<h2 id="we-built-this-to-be-questioned">We built this to be questioned</h2>
<p>Before I came to blockchain analytics, I spent years in academia studying the formal correctness of distributed systems. My work was proving, mathematically, that code and protocols behave correctly under every possible execution variant. Not most of them. All of them. In that world, there isn’t a “good enough.” There’s proof, or there’s no proof.</p>
<p>I left academia to apply that thinking to real-world problems, first in financial infrastructure where failure is enormously expensive, and eventually to blockchain analytics, where failure directly impacts peoples’ livelihoods. I’ve now spent nearly a decade as Chainalysis’s Chief Scientist, and I’m ultimately responsible for the quality of our data. That responsibility is something I carry into every decision about how our systems work and the claims they make.</p>
<p>I mention this background because it explains something about how I approach this field, and why the following moment that happened a few years back changed everything.</p>
<h2 id="the-moment">The moment</h2>
<p>A customer came to me with a problem. They had two blockchain analytics tools giving them two very different answers about the same deposit address. Ours called it a gambling service. The other tool called it CSAM.</p>
<p>This was not a disagreement about whether an address belongs to Exchange A or Exchange B. Rather, it was a  disagreement where one answer means a person placed a bet, and the other means they may have purchased child sexual abuse material.</p>
<p>I looked at it and quickly understood what had happened. Small, regular payments of similar size and frequency can look alike if all you’re doing is matching statistical patterns. A small-time gambler and something far darker can produce similar transaction footprints when viewed through a narrow enough lens. That’s a dangerous conclusion, and a reckless foundation to build it on – no evidence, just appearance.</p>
<p>That kind of conclusion cannot easily be independently proven by the people who act on it. People rely on this data and may treat it as fact. We have proven that it <i>can</i> be relied on, if done right. This, however, was exploitation of that trust. And it could have terrible consequences.</p>
<h2 id="building-research-grade-systems-for-a-field-that-didnt-exist">Building research-grade systems for a field that didn’t exist</h2>
<p>When I joined this space, blockchain analytics wasn’t an established discipline. There were no textbooks, no accreditation bodies, no precedent. The problems were novel. It was research. And we were building systems to be used by people who didn’t fully technically comprehend blockchains, people who relied on the correctness of our work and trusted it. Law enforcement agents building cases. Compliance teams making decisions that affect real people and their access to money. Prosecutors presenting evidence in court.</p>
<p>So I did what came naturally: applied academic rigor to everything we built. If it could withstand peer review, it was good enough. If it couldn’t, discard. We drew hard lines between what could be proven through deterministic, reproducible on-chain analysis, and what required intelligence tradecraft. We enumerated failure modes and safeguarded against them. We treated the structural layer of our analysis as a scientific discipline, because that’s what it is.</p>
<p>When you’ve spent years proving systems correct under all conditions, you don’t ship something and hope it holds up. You build it so you can prove it holds up.</p>
<h2 id="rigor-is-a-philosophy-not-a-phase">Rigor is a philosophy, not a phase</h2>
<p>That standard wasn’t something we outgrew as the company scaled or the blockchain ecosystem evolved. As new chain architectures emerged, as the complexity of on-chain activity grew exponentially, we kept the bar exactly where it was and improved our operational processes.</p>
<p>When our methodology was subjected to full <i>Daubert</i> scrutiny in federal court in <i>United States v. Sterlingov</i>, it was found admissible across every criterion. I never doubted that outcome, because I knew our methods could stand up to peer review.</p>
<p>When independent researchers at Delft University in collaboration with law enforcement conducted the only empirical validation study of attribution accuracy against ground truth from seized infrastructure, we welcomed it. We let the results be published. We treated it as what it was: the kind of external scrutiny that any legitimate discipline should invite. Another provider tried to suppress that same study through legal threats. That tells you something. No. It tells you everything.</p>
<p>As the field grew, new entrants arrived. And with them came a gradual erosion that I’ve watched with growing concern. Definitions got looser. Machine learning outputs started being treated as forensic facts. I started getting questions from customers about data quality issues that shouldn’t exist if the underlying methodology were sound. The CSAM-versus-gambling moment was the most visceral, but it wasn’t the only one, and they haven’t stopped coming.</p>
<h2 id="the-vocabulary-gap">The vocabulary gap</h2>
<p>The field is still young and the technology is genuinely new. But the deeper problem isn’t that the investigators, regulators, and courts who depend on this data don’t fully understand the underlying mechanics. It’s that they shouldn’t have to. You can’t expect everyone investigating crime in this space to appreciate every nuance and technical aspect. That’s what science gives you. Blockchain analytics hasn’t formalized that yet since the space is new. We’re building toward the kind of standards that mature scientific disciplines have established.</p>
<p>That’s why we wrote the ontology. Neither as a product specification nor a marketing document, but formal paper that outlines the standards we have upheld since our founding that breaks down the work we do into its constituent parts, assigns each an evidentiary standard, and gives the industry a vocabulary for accountability.</p>
<p>It defines two tiers. The layer that determines whether addresses share common control, must meet a standard of structural soundness: deterministic, reproducible, auditable, with known and documented failure modes. The attribution layer, linking those addresses to a named entity, follows a structured and recognizable confidence framework: source characterization with documented reasoning requirements. Both are rigorous. But they’re different <i>kinds</i> of rigor, and conflating them is how you confuse people, and failing to appreciate them is how you end up labeling a gambler as a CSAM purchaser.</p>
<h2 id="why-this-makes-me-proud">Why this makes me proud</h2>
<p>This paper formalizes the principles that have guided our methodology since our founding, while acknowledging that our implementation continues to evolve<i>.</i> It required us to <i>name</i> what we’ve been doing all along. The standards it defines are the standards we already hold ourselves to. The bright lines it draws are bright lines we drew years ago, because nothing less would withstand peer review.</p>
<p>The consumers of blockchain analytics data don’t always have the information to perform their own peer review. What makes me proud is working for a company that does not violate the trust those people place in us. Every system we designed, every heuristic we deployed, every analytical claim we made was built with the assumption that it would one day be examined by someone adversarial, skeptical, and technically capable, and that it needed to hold up. And it has held up. Because we built it that way.</p>
<p>But pride in our own work isn’t enough. The people affected by blockchain analytics outputs, the subjects of investigations, the users flagged by compliance systems, the defendants in criminal cases, deserve an industry that holds itself to this standard collectively. This paper is a first step, not a final word. We’re publishing our definitions because someone needs to take the lead in responsible transparency. Someone has to establish the boundaries. We believe we have. Now we’re inviting the industry to build on them with us.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dawnswap.finance/2026/07/29/an-ontology-for-accountability-defining-what-data-quality-means-in-blockchain-analytics/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Inside a Sandwich Attack: Lessons From the $7.5 Million Heist Against JaredfromSubway.eth</title>
		<link>https://www.dawnswap.finance/2026/07/29/inside-a-sandwich-attack-lessons-from-the-7-5-million-heist-against-jaredfromsubway-eth/</link>
					<comments>https://www.dawnswap.finance/2026/07/29/inside-a-sandwich-attack-lessons-from-the-7-5-million-heist-against-jaredfromsubway-eth/#respond</comments>
		
		<dc:creator><![CDATA[dexadm]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 06:37:40 +0000</pubDate>
				<category><![CDATA[Intel on Cryptos]]></category>
		<category><![CDATA[heist]]></category>
		<category><![CDATA[jaredfromsubway]]></category>
		<guid isPermaLink="false">https://www.dawnswap.finance/?p=46</guid>

					<description><![CDATA[Summary JaredfromSubway.eth, the most prolific sandwich-attack bot on Ethereum, was drained of at least $7.5 million in a reverse honeypot exploit on June 20–21, 2026. An unknown attacker deployed 66 fake token contracts to trick the bot into granting token-spending approvals, then swept its real assets in a single coordinated transaction. The stolen funds — &#8230; <a href="https://www.dawnswap.finance/2026/07/29/inside-a-sandwich-attack-lessons-from-the-7-5-million-heist-against-jaredfromsubway-eth/" class="more-link">Continue reading <span class="screen-reader-text">Inside a Sandwich Attack: Lessons From the $7.5 Million Heist Against JaredfromSubway.eth</span></a>]]></description>
										<content:encoded><![CDATA[<h2 id="summary">Summary</h2>
<ul>
<li aria-level="1">JaredfromSubway.eth, the most prolific sandwich-attack bot on Ethereum, was drained of at least $7.5 million in a reverse honeypot exploit on June 20–21, 2026.</li>
<li aria-level="1">An unknown attacker deployed 66 fake token contracts to trick the bot into granting token-spending approvals, then swept its real assets in a single coordinated transaction.</li>
<li aria-level="1">The stolen funds — ETH and stablecoins — were converted to ETH and sent to Tornado Cash. No funds have been recovered.</li>
<li aria-level="1">The exploit underscores the importance of revoking unused approvals and vetting smart contracts before interacting with them on-chain.</li>
</ul>
<p>&nbsp;</p>
<p>Ethereum’s most notorious sandwich attacker just got compromised. Over the weekend, JaredfromSubway.eth — who spent years squeezing other traders for profit — lost at least $7.5 million in crypto to a trap disguised as a lucrative trade.</p>
<h2 id="how-sandwich-attacks-work">How sandwich attacks work</h2>
<p>The attack struck in Ethereum’s mempool: the waiting room where on-chain trades go before they finalize. Integral to the way Ethereum works, its mempool is viewable by anyone – even rival traders. Savvy operators like JaredfromSubway.eth have long forged an edge with mempool intelligence. They front-run victims’ yet-to-finalize orders, pushing up the price for the user. Then, they back-run them too, creating an arbitrage sandwich.</p>
<h2 id="ethereums-most-prolific-sandwich-bot">Ethereum’s most prolific sandwich bot</h2>
<p>This highly profitable trading strategy is controversial and unseemly, but also widespread. JaredfromSubway.eth has made tens of millions of dollars sandwiching other traders since 2023. His bot hunts for opportunities to extract value across <a href="https://www.chainalysis.com/glossary/defi/" target="_blank" rel="noopener">DeFi</a>, monitoring token pools for imbalances and inefficiencies, and, when it finds one, making a sandwich to capture some cash.</p>
<h2 id="how-the-75-million-honeypot-exploit-worked">How the $7.5 million honeypot exploit worked</h2>
<p>That’s what happened over the weekend. Jared’s bot spotted a series of pools that it could exploit. So it went through the normal motions – including granting spending approvals – needed for executing automated transactions quickly enough for the mempool.</p>
<p>But the <a href="https://www.chainalysis.com/glossary/smart-contracts/" target="_blank" rel="noopener">smart contracts</a> to which his bot granted spending approvals were actually honeypots. Their token trading pairs were illegitimate stooge assets; there wasn’t a real profit for Jared to extract. His bot didn’t register this. Over multiple transactions, it kept granting approvals to these malicious contracts — permissions that were never revoked. Once enough had accumulated, a tripwire smart contract activated and drained JaredfromSubway.eth of at least $7.5 million.</p>
<h2 id="following-the-money-laundering-through-tornado-cash">Following the money: laundering through Tornado Cash</h2>
<p>Stolen assets included ETH and millions of dollars in stablecoins. Keeping the assets in stablecoins presented a risk to the attacker; the stablecoins’ issuers could choose to freeze the funds. That may be why within minutes of acquiring the stablecoins, the attacker swapped them into ETH as well – shielding the stolen assets from an easy freeze.</p>
<p>Using <a href="https://www.chainalysis.com/product/reactor/?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=dra-search-brand&amp;utm_content=investigations-solution&amp;utm_category=noram&amp;utm_term=chainalysis%20reactor&amp;qgad=762410420593&amp;qgterm=chainalysis%20reactor&amp;utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=%7Bcampaign%7D&amp;utm_term=chainalysis%20reactor&amp;utm_content=762410420593&amp;hstk_creative=762410420593&amp;hstk_campaign=15152580614&amp;hstk_network=googleAds&amp;gad_source=1&amp;gad_campaignid=15152580614&amp;gbraid=0AAAAADNIJZCKAJVu7JSri6YdxpvtOo--K&amp;gclid=CjwKCAjwgO7RBhBKEiwAZNP85tCbQE9v7GErqz4JRQ3KKB89FRHfFPe_Ck52oqN0EbPhc5GnM9EINBoCPakQAvD_BwE" target="_blank" rel="noopener">Reactor</a>, we can see that over the following days, the attacker split their ill-gotten gains across other wallets. This kicked off a chain of transfers leading into <a href="https://www.chainalysis.com/blog/tornado-cash-sanctions-challenges/" target="_blank" rel="noopener">Tornado Cash</a>, a tool that obfuscates the flow of funds.</p>
<p><a class="js-lightbox" href="https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor.png" data-gallery="post-gallery" target="_blank" rel="noopener"><picture><source srcset="https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor.avif 1246w" type="image/avif" sizes="(max-width: 1246px) 100vw, 1246px" /><img fetchpriority="high" decoding="async" class="aligncenter wp-image-29796 size-full" src="https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor.png" sizes="(max-width: 1246px) 100vw, 1246px" srcset="https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor.png 1246w, https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor-800x367.png 800w, https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor-150x69.png 150w, https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor-300x138.png 300w, https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor-750x344.png 750w, https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor-948x435.png 948w, https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor-1200x551.png 1200w, https://www.chainalysis.com/wp-content/uploads/2026/06/honeypot-reactor-1024x470.png 1024w" alt="" width="1246" height="572" /></picture></a></p>
<h2 id="why-this-matters-for-every-defi-user">Why this matters for every DeFi user</h2>
<p>The mechanics of this exploit offer a lesson for anyone transacting on-chain.</p>
<h3 id="unrevoked-token-approvals-are-standing-invitations">Unrevoked token approvals are standing invitations</h3>
<p>The attack worked because Jared’s bot granted token-spending approvals to smart contracts it never bothered to vet. Every day, ordinary DeFi users do the same thing. They approve contracts to spend their tokens – often granting unlimited permissions to code they’ve never read. Those approvals don’t expire. Each is a standing invitation for someone else to move your money. Jared’s bot had dozens of them pointing at malicious contracts, and it never noticed. Most wallets are no different.</p>
<h3 id="the-counterparty-problem-with-unverified-contracts">The counterparty problem with unverified contracts</h3>
<p>Then there’s the counterparty problem. In traditional finance, you know who’s on the other side of a trade. On-chain, the counterparty is the smart contract itself – and if that contract is unverified, you’re essentially signing a deal you can’t read. Jared’s bot interacted with 66 fake contracts that mimicked legitimate tokens. A manual review of the code – or even a basic check of deployment history – might have flagged them. But the bot was optimized for speed. It skipped due diligence, and lost $7.5 million for it.</p>
<h3 id="how-to-protect-yourself-from-honeypots">How to protect yourself from honeypots</h3>
<p>Revoke approvals you no longer need. Vet the contracts you interact with – check whether they’re verified on Etherscan, look at who deployed them. Be skeptical of new pools with no track record. Otherwise, you risk getting rolled.</p>
<h2 id="faqs">FAQs</h2>
<p><b>What is a sandwich attack?</b></p>
<p>A sandwich attack is a predatory trading strategy where a bot monitors Ethereum’s mempool – the public waiting room for pending transactions – and spots a trade it can exploit. The bot front-runs the victim’s order with its own buy, pushing the price up, then lets the victim’s trade execute at the inflated price. Immediately after, the bot sells for a profit. The victim gets a worse deal; the bot pockets the difference. It’s called a sandwich because the victim’s trade is squeezed between the bot’s two orders – the bread on either side.</p>
<p><b>Who is JaredfromSubway.eth?</b></p>
<p>JaredfromSubway.eth is the pseudonymous operator of Ethereum’s most prolific sandwich bot, active since 2023. At its peak, the bot’s prolific sandwich activity cost traders an estimated $60 million a year. It was frequently the single largest gas consumer on the entire network.</p>
<p><b>How did the attack unfold?</b></p>
<p>An unknown attacker deployed 66 fake token contracts that mimicked legitimate assets like WETH, USDC, and USDT, and paired them with fraudulent liquidity pools. To Jared’s bot, these looked like easy sandwich targets. As the bot moved to exploit them, it granted token-spending approvals to the attacker’s contracts. But those approvals were never consumed or revoked. They stayed open, giving the attacker a means to move the bot’s real assets. Once enough approvals had accumulated, the attacker triggered a single coordinated transaction that swept approximately $7.5 million in ETH and stablecoins from the bot’s wallets. The stolen funds were quickly converted to ETH and sent through Tornado Cash.</p>
<p><b>How can I avoid getting hacked this way?</b></p>
<p>Revoke token approvals you no longer need. Vet the contracts you interact with before you sign anything. Check whether the contract is verified on Etherscan. Look at when it was deployed and by whom. Be wary of new, unaudited pools offering too-good-to-be-true trades – it may have been designed that way on purpose.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dawnswap.finance/2026/07/29/inside-a-sandwich-attack-lessons-from-the-7-5-million-heist-against-jaredfromsubway-eth/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Chainalysis Research and Analysis July 2, 2026</title>
		<link>https://www.dawnswap.finance/2026/07/29/chainalysis-research-and-analysis-july-2-2026/</link>
					<comments>https://www.dawnswap.finance/2026/07/29/chainalysis-research-and-analysis-july-2-2026/#respond</comments>
		
		<dc:creator><![CDATA[dexadm]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 06:25:46 +0000</pubDate>
				<category><![CDATA[Intel on Cryptos]]></category>
		<guid isPermaLink="false">https://www.dawnswap.finance/?p=42</guid>

					<description><![CDATA[Chainalysis Research and Analysis Compliance teams, regulators, and investigators rely on blockchain analytics to uncover illicit activity and support enforcement actions, but every outcome depends on the quality of the underlying data. A single incorrect attribution can discredit related insights, derail investigations, and trigger wrongful customer terminations. Evaluating a provider requires scrutiny of the methodology, &#8230; <a href="https://www.dawnswap.finance/2026/07/29/chainalysis-research-and-analysis-july-2-2026/" class="more-link">Continue reading <span class="screen-reader-text">Chainalysis Research and Analysis July 2, 2026</span></a>]]></description>
										<content:encoded><![CDATA[<p>Chainalysis Research and Analysis</p>
<p>Compliance teams, regulators, and investigators rely on blockchain analytics to uncover illicit activity and support enforcement actions, but every outcome depends on the quality of the underlying data. A single incorrect attribution can discredit related insights, derail investigations, and trigger wrongful customer terminations. Evaluating a provider requires scrutiny of the methodology, evidence, and safeguards behind every conclusion.</p>
<p>&#8211; Providers should explain whether common ownership is established deterministically or inferred probabilistically, and demonstrate how techniques adapt to distinct blockchain architectures.<br />
&#8211; A label backed by law enforcement-seized data is fundamentally different from one based on an anonymous tip, and grouping logic should hold up even if a label is removed.<br />
&#8211; Robust attribution requires differentiating between who interacts with an address and who ultimately controls it, particularly for exchange deposit addresses and nested custodial entities.<br />
&#8211; Providers should be transparent about whether their methods have satisfied legal standards like Daubert and how they distinguish machine learning outputs from evidence-based conclusions.<br />
&#8211; A reliable provider can walk you through exactly how any specific cluster was constructed and what evidence supports it.</p>
<h2 id="summary">Summary</h2>
<ul>
<li aria-level="1">OFAC updated its <a href="https://www.chainalysis.com/blog/ofac-sanctions-isis-financial-facilitators-june-2026/" target="_blank" rel="noopener">ISIS Khorasan (ISIS-K) designation</a> to include 134 cryptocurrency wallet addresses (131 on TRON and 3 on Monero).</li>
<li aria-level="1">In a separate action, OFAC sanctioned individuals linked to the Latin American criminal organization Primeiro Comando da Capital (PCC), which moved illicit proceeds cross-border using crypto.</li>
</ul>
<p>&nbsp;</p>
<p>On July 1, 2026, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) <a href="https://ofac.treasury.gov/recent-actions/20260701" target="_blank" rel="noopener">updated</a> its designation of ISIL Khorasan (ISIS-K) and added 134 cryptocurrency wallets as identifiers. ISIS-K is the Islamic State’s Pakistani and Afghan affiliate.</p>
<p>ISIS-K was first flagged as a Specially Designated Terrorist Group in <a href="https://web.archive.org/web/20160119055307/https://www.treasury.gov/press-center/press-releases/Pages/jl0188.aspx" target="_blank" rel="noopener">September 2015</a>. Today’s sanctions update includes 3 <a href="https://www.chainalysis.com/blog/all-about-monero/" target="_blank" rel="noopener">Monero</a> (XMR) addresses and 131 TRON (TRX) addresses. Tether has frozen the balances on all 131 TRON addresses.</p>
<h2 id="what-is-isis-k-and-what-is-their-connection-to-crypto">What is ISIS-K and what is their connection to crypto?</h2>
<p>ISIS-K is a regional branch of Islamic State that is active throughout Afghanistan, Pakistan, and several former Soviet Union countries in Central Asia. The group has been responsible for numerous terror attacks targeting civilians in multiple countries, including Afghanistan, Pakistan, and Russia. Their media branch, al-Azaim Media Foundation, spreads propaganda through the publication <i>Voice of Khorasan</i> and has historically solicited crypto through donation campaigns on various websites and messaging platforms. Chainalysis has collected historical donation addresses on Tron, Monero, and Bitcoin.</p>
<p><a class="js-lightbox" href="https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1.png" data-gallery="post-gallery" target="_blank" rel="noopener"><picture><source srcset="https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1.avif 1454w" type="image/avif" sizes="(max-width: 1454px) 100vw, 1454px" /><img decoding="async" class="aligncenter wp-image-29852 size-full" src="https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1.png" sizes="(max-width: 1454px) 100vw, 1454px" srcset="https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1.png 1454w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1-800x690.png 800w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1-150x129.png 150w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1-300x259.png 300w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1-750x647.png 750w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1-948x818.png 948w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1-1200x1035.png 1200w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-1-1024x883.png 1024w" alt="" width="1454" height="1254" /></picture></a></p>
<p>Like many earlier public terrorist financing campaigns, donations to al-Azaim were historically smaller in size, reflecting individuals’ modest means but demonstrating their incentive to support the group.</p>
<h2 id="on-chain-analysis-isis-ks-tron-wallets">On-chain analysis: ISIS-K’s TRON wallets</h2>
<p>At the center of Wednesday’s sanctions are 131 TRX addresses controlled by the group. Those wallets have received over $1.4 million since 2023 and sent over $880,000. As shown in the <a href="https://www.chainalysis.com/product/reactor/" target="_blank" rel="noopener">Chainalysis Reactor</a> graph below, the wallets have heavy exposure to mainstream services. Several of the designated wallets also sent funds to Syria-based crypto exchangers.</p>
<p><a class="js-lightbox" href="https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2.png" data-gallery="post-gallery" target="_blank" rel="noopener"><picture><source srcset="https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2.avif 1234w" type="image/avif" sizes="(max-width: 1234px) 100vw, 1234px" /><img decoding="async" class="aligncenter wp-image-29853 size-full" src="https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2.png" sizes="(max-width: 1234px) 100vw, 1234px" srcset="https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2.png 1234w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2-800x685.png 800w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2-150x128.png 150w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2-300x257.png 300w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2-750x642.png 750w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2-948x811.png 948w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2-1200x1027.png 1200w, https://www.chainalysis.com/wp-content/uploads/2026/07/isis-graph-2-1024x876.png 1024w" alt="" width="1234" height="1056" /></picture></a></p>
<h2 id="past-actions-against-isis">Past actions against ISIS</h2>
<p>U.S. sanctions underscore how ISIS and its affiliates use cryptocurrency to fund their global operations.</p>
<p>In 2023, OFAC sanctioned Maldives-based ISIS-K operative Ali Shafiu; <a href="https://www.chainalysis.com/blog/ofac-sanctions-al-qaeda-isis-ali-shafiu/" target="_blank" rel="noopener">Chainalysis</a> found that Shafiu’s TRON interacted with exchange deposit addresses that also had ties to Iranian exchanges. And just last month, <a href="https://www.chainalysis.com/blog/ofac-sanctions-isis-financial-facilitators-june-2026/" target="_blank" rel="noopener">OFAC sanctioned</a> a network of Syrian money service businesses that served as a cash-out for ISIS financiers. Chainalysis’ investigation of the operative at the center of that action, Miloud Abderrahmane, shuttled money from mainstream exchanges to Middle Eastern donation campaigns.</p>
<h2 id="brazil-syndicate-separately-targeted">Brazil syndicate separately targeted</h2>
<p><a href="https://home.treasury.gov/news/press-releases/sb0549" target="_blank" rel="noopener">In a separate action</a>, OFAC designated two Brazilian nationals and four companies for their links to Primeiro Comando da Capital (PCC), a Latin American criminal group with operatives in the U.S. and São Paulo, its homebase. According to OFAC, the group’s <a href="https://www.chainalysis.com/blog/crypto-drug-sales-darknet-markets-2026/" target="_blank" rel="noopener">drug traffickers</a> <a href="https://www.chainalysis.com/blog/2026-crypto-money-laundering/" target="_blank" rel="noopener">laundered</a> more than $30 million of illicit proceeds generated in the U.S, utilizing cryptocurrency to move funds back to Brazil.</p>
<p>This marks OFAC’s third action against PCC and its operatives, following the December 2021 designation of PCC as an organization and the March 2024 designation of Diego Macedo Gonçalves do Carmo for his role in laundering significant sums for the group.</p>
<h2 id="impact-on-cryptocurrency-compliance">Impact on cryptocurrency compliance</h2>
<p>For global VASPs and financial institutions, these actions require immediate updates to sanctions screening and transaction monitoring protocols.</p>
<p>With Chainalysis’s solutions, organizations can monitor and detect exposure to these high-risk networks. We have labeled the relevant cryptocurrency addresses associated with today’s designations in our product suite to ensure our customers can proactively identify exposure and maintain global compliance standards.</p>
<h2 id="faqs">FAQs</h2>
<p><b>What was updated in the ISIS-K designation?</b></p>
<p>OFAC added 131 TRON wallet addresses and 3 Monero wallet addresses to the existing ISIS-K designation.</p>
<p><b>What is ISIS-K?</b></p>
<p>ISIS-K is a regional branch of Islamic State that operates in Central and South Asia. Their media branch Voice of Khorasan has historically solicited donations via crypto.</p>
<p><b>Who did OFAC designate in the PCC-related action?</b></p>
<p>OFAC designated two Brazilian nationals, Victor Henrique de Oliveira Shimada and Stella Stefanie Nunes Henrique de Oliveira, along with four companies: Victory Trading, Pixwave, and Wave (Brazil), and Avenidas Flutuantes (Portugal).</p>
<p><b>How did the PCC network use cryptocurrency?</b></p>
<p>According to OFAC, the network laundered more than $30 million in illicit proceeds generated in and around multiple U.S. cities, utilizing cryptocurrency to move funds back to Brazil on behalf of PCC.</p>
<p><b>What are the compliance requirements following these designations?</b></p>
<p>All U.S. persons must block property and interests in property of the designated individuals and entities. Because the designations carry secondary sanctions risks, foreign financial institutions that facilitate transactions for these parties risk being cut off from the U.S. financial system.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.dawnswap.finance/2026/07/29/chainalysis-research-and-analysis-july-2-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
