WalletDNA
← Video tutorials

Following crypto across chains

3:23 · Investigators, analysts, and anyone advising a victim

Follow a publicly flagged phishing drainer from Ethereum onto Arbitrum: tell a bridge you can follow from one you can't, decode the recipient from the deposit transaction itself, and see the flag carry over to the same wallet on the other chain.

Transcript

Stolen crypto rarely stays on one blockchain. Moving it to another chain through a bridge is one of the most common ways a trail goes cold, because most tools stop at the bridge contract. This video follows a real wallet across that boundary, and shows exactly where the evidence is solid and where it isn't.

Our subject is a public one: a wallet that two threat-intelligence feeds, ScamSniffer and MistTrack, flag as a phishing drainer. Paste the address and analyze. WalletDNA shows the label, where it came from, and an elevated risk level.

On the canvas, the violet diamonds are bridges, and this wallet has two. Start with Across. WalletDNA says plainly that the destination chain isn't resolved on-chain. Across is a router: it serves many chains, and the destination isn't written into the contract's address, so WalletDNA won't guess. The node isn't expandable either. A bridge is a shared contract, and expanding it would pull in thousands of strangers, not this wallet's money.

The second is a small deposit into Arbitrum's own bridge. Arbitrum's bridge is a canonical bridge. It only goes to Arbitrum, so the destination chain is a fact, not an inference. That difference is the one that matters when someone challenges your work.

For the full record, open this wallet's bridge exits. The report lists every send to a known bridge, dated, with its transaction: the Across exit, and the Arbitrum deposit from April 2023. It's small, and small transfers are easy to overlook, but a small first transfer is a common way to test a route, so every exit is listed, whatever its size.

Click Continue on Arbitrum. Before anything is charged, WalletDNA reads the deposit transaction itself and decodes which address it credited. Here it's the sender's own address on Arbitrum. On other deposits it's a completely different wallet, which is exactly why it's read from the transaction rather than assumed. Confirm, and it uses one analysis.

A new report, on Arbitrum. The banner records the crossing: where the trail came from, where it arrived, how the recipient was determined, and the deposit transaction that proves it. Both addresses open on their block explorers, so anyone can check this without taking our word for it.

And the flag follows the wallet. This address has no contract code, so the same private key controls it on Arbitrum as on Ethereum. The drainer label recorded on Ethereum applies here too, and the report says exactly where that label came from, rather than claiming anything about a particular Arbitrum transaction.

And on Arbitrum, this wallet is anything but quiet: more than two hundred transactions and dozens of counterparties. The trail didn't end at the bridge. It kept going, and now you can follow it.

And the Across exit? It stays open until you have the receiving address, usually from the bridge operator. WalletDNA marks it unresolved instead of drawing a confident line to the wrong wallet, because a wrong cross-chain link is worse than none.

How bridge tracing works, and where its limits are, is documented at walletdna.com/methodology.