This case study documents a cryptocurrency scam involving the theft of stablecoins from a victims Solana wallet, followed by systematic laundering through asset swaps, cross-chain bridges, and eventual deposit into an online gambling platform.
The investigation traces funds from the victim wallet, through a scammer-controlled intermediary wallet, into SideShift.ai, and finally into a Shuffle.com hot wallet on Ethereum.
Victim Address (Solana):
E1QkRa4gaUxyR6nrEHGQYZoMnDdmP41mxFkGMPDrWjbv
1. USDT Transfer
Amount: $5,049.87 USDT
Transaction:
https://solscan.io/tx/zCuRe9NscMbRXNnEcyYY8qC1woaPoJM7aCEBp8i9MVrc3ARtAkQAMk2mr6UuFprFBJ6HnSP6AU7SJ4oPJiYQqgD
2. USDC Transfer
Amount: $220 USDC
Transaction:
https://solscan.io/tx/C4ThkCjYYM55yFpbiCWq4U8HwEXGZc217kjKNhuhBFarvUknVJxmbTqT4MdjEHAZqaQzbY9GMfbnP6uEQvdQvV8
Scammer Address (Solana):
6dw1ZzrGKeEsCqjyQb5ZdeCSmHxhHmsg6QhPM48r9PDf
Following receipt of the stolen funds, the scammer:
1) Converted USDT and USDC into wSOL
2) Swapped wSOL into native SOL
3) Distributed SOL into multiple outgoing transactions
4) Sent funds to SideShift.ai for cross-chain laundering
After converting the assets into SOL, the scammer split the funds into four transfers directed to SideShift.ai.
The origin of the 15 SOL transaction could not be conclusively established during this investigation. The remaining transfers were successfully reconstructed.
The incoming 5 SOL transaction arrived at SideShift's Solana hot wallet at 14:56:06 UTC.
SideShift then converted the funds into 1,040 USDC (ERC-20) before forwarding them to the destination wallet.
Outgoing
https://etherscan.io/tx/0xea4089669e693d6277be86f5c68cff129e507e4b7973c2ed503cda6a6e11d9b8
The 3.5 SOL transfer reached SideShift at 15:01:48 UTC.
Outgoing
https://etherscan.io/tx/0xa0ff07ad4c6ff69d87a10890d04b9a2b3d8f145676756ece25eb5058c6e98b70
The final traced transfer consisted of 1.5 SOL.
Outgoing
https://etherscan.io/tx/0xc12ec91245a82711069993720518ed964e264a8c4c80fbc5f936b087bcc66697
Shuffle.com Hot Wallet (Ethereum):
0x5a82340EA0A1756296cb511aAA2BE6ebD8A27e1E
This indicates the scammer ultimately deposited stolen funds into Shuffle.com, likely for gambling, mixing, or withdrawal to another wallet.
• Stolen funds originated from a verified victim wallet
• Assets were converted and laundered using token swaps (USDT/USDC u2192 SOL) and cross-chain swapping (Solana u2192 Ethereum)
• SideShift.ai was used as the primary laundering bridge
• Final destination was a centralized gambling platform (Shuffle.com)
• Transaction timing and values strongly correlate across chains
1) Report the incident to local law enforcement with all transaction hashes and wallet addresses
2) Submit a formal report to Shuffle.com requesting account review and potential fund freeze
support@shuffle.com
3) Preserve all blockchain evidence for compliance, recovery efforts, or civil proceedings
This case demonstrates a common modern laundering pattern: Stablecoins u2192 Native Asset u2192 Cross-Chain Swap u2192 Gambling Platform. The transparency of public blockchains allowed for full traceability across networks, highlighting the importance of on-chain analysis in crypto crime investigations.