A complete audit of the MetaTronics payout infrastructure across two chains. Every automated row in the operator’s withdrawal ledger is reconciled against primary chain data; the funding chain is traced back to a payment gateway; the cross-chain crossing is characterised statistically and confirmed at both ends; and nine address attributions carried in the 3 August 2026 interim report are corrected or withdrawn.
What this audit set out to answer.
Questions 1 to 5 are answered. Question 6 produced nine corrections, set out in section K.
Primary sources, with provenance and limits. Full hashes in Appendix 2.
| Source | Content | Provenance | Known limit |
|---|---|---|---|
| Operator withdrawal ledger (XLSX) | 4,953 completed external withdrawals, $594,242.93, 1,608 people, 11 Mar – 21 Sep 2026 | Production database snapshot, 21 Sep 2026 07:13 UTC, supplied to the investigation | One branch only; excludes internal transfers, rejected, pending and failed requests |
| BSC payout wallet exports | 10 files, 31,132 rows, 22 Jul – 22 Sep 2026 | BscScan, USDT contract filtered, pulled 22 Sep 2026 | Window opens at the ledger's first payout, not the wallet's first activity |
| Branch leader wallet exports | 39 Advanced Filter pages, 3,793 unique rows, 30 Nov 2022 – 22 Sep 2026 | BscScan, pulled 22 Sep 2026 | Two pages duplicate one window |
| BSC funding wallet exports | 1,321 rows (current funder); 4,517 token rows + 551 normal transactions (wallet A) | BscScan, pulled 22 Sep 2026 | No explorer-stated totals captured for comparison |
| TRON exports | Hub 3,948 of 8,237 transfers; payout wallet 1,222; crossing wallet 178 of 449; two funders capped at 10,000 rows | TronScan, pulled 22 Sep 2026 | Several are partial; all TRON totals are floors |
| Video frame | Withdrawal form showing recipient address and $1,800 from Income balance | Screen recording published by the account holder | Single frame; audio not analysed |
| Admin-panel notifications | 19 withdrawal events, 23–25 Apr 2026, with request IDs, amounts and addresses | Leaked operator Telegram bot output, forwarded to the investigation | Transcribed by hand from screenshots |
What each row can and cannot establish — this governs everything downstream.
The ledger's own Methodology sheet defines three levels of blockchain proof. The distinction is not cosmetic: two of the three are the operator's reconstruction rather than its record.
| Level | Basis | Rows | USD | Evidential weight |
|---|---|---|---|---|
| 1 — Automated | Hash stored by the payment service at payment time, from 21 Jul 2026 | 4,247 | 508,768.36 | Operator's own contemporaneous record |
| 2 — Manual, matched | Operator later searched the recipient's address for an inbound transfer of similar amount and time, then recorded whoever sent it | 270 | 21,235.19 | Weak Produces false attributions — see section K |
| 3 — Not identified | Operator marked as paid; no transfer found | 436 | 64,239.38 | Unresolved, not disproved — 20 have since been resolved on chain |
Two structural checks on the file itself: all 4,517 hashes are well-formed for their stated network, and every hidden hyperlink in the Explorer link column contains its own row's hash and points at the correct explorer. No internal inconsistency was found.
Ledger against primary chain data, matched on hash, recipient and amount simultaneously.
3,536 ledger rows from the automated payout wallet, $418,914.19 requested and $418,770.19 sent. All 3,536 matched. Coverage was assembled from ten export windows; two initial files returned exactly 5,000 rows and were re-pulled after the truncation was detected, closing gaps of 50.8 and 71.7 hours. Merged coverage is continuous from 22 Jul 05:33:37 to 22 Sep 18:24:56.
711 ledger rows from the automated TRC-20 payout wallet. All 711 matched. Requested $89,854.17 against $87,721.17 on chain — a difference of exactly 3.00 on every row without exception.
Pulling the operator's own upstream wallets resolved 22 of the 436 level-3 rows: five from hub B (4–8 Jul), fourteen from wallet A (9 Jul – 1 Aug), one from the current funder (11 Sep), and two more from the funder's outflows. All are member withdrawals paid from a funding wallet rather than a payout wallet, which is why the operator's own reconciler — searching only the wallets it knew — never found them.
One payout wallet, a rotating series of funders, and no upstream the operator controls.
The automated payout wallet received real USDT from exactly four addresses across the covered period, totalling 577,720. They hand over in sequence rather than operating in parallel.
| Source | Transfers | USDT | Period | What it is |
|---|---|---|---|---|
| Wallet A (interim report) | 54 | 193,200 | 22 Jul – 13 Aug | Operator funding wallet |
| Second funder | 4 | 28,500 | 13 – 15 Aug | Operator funding wallet |
| Current funder | 45 | 346,520 | 16 Aug – 21 Sep | Operator funding wallet |
| Hub B (interim report) | 1 | 9,500 | 31 Aug | Operator wallet, pass-through same morning |
Wallet A's own export records 58 transfers and 193,480 to the payout wallet; the four-transfer difference falls on 20–21 July, before the payout wallet's export window opens. Both figures are correct for their windows, and the difference establishes that the payout wallet was active before 22 July.
Wallet A: 268,159.71 in, 268,159.42 out, 0.29 retained. Current funder: 374,959.20 in, 373,665.47 out, about 1,294 retained. Payout wallet: 577,720 in, 571,061.74 out, about 6,887 retained. No wallet accumulates.
Wallet A signed 551 transactions: 546 plain transfers, 3 approvals, 2 calls to bridge contracts, zero failures. No DEX router, no perpetuals venue, no lending or staking contract appears anywhere in its history.
Every source of funds into the funding wallets resolves to third-party infrastructure: the Bridgers contracts, the HOT Bridge treasury, and Binance hot wallets. No operator-controlled wallet upstream of the payout system exists on this chain. The money arrives already bridged.
A hub an order of magnitude larger than the ledger implies.
The TRON hub was created on 11 January 2026. In the portion exported — 3,948 of a stated 8,237 transfers — it handled 1,826,293.52 USDT in and 1,781,510.86 out, paying 1,091 distinct counterparties.
| Destination class | Transfers | USDT | Reading |
|---|---|---|---|
| Operator wallets | 240 | 895,283.89 | Payout wallet, crossing wallet, and two further nodes |
| Addresses outside the ledger | 3,004 | 868,366.98 | 996 addresses, median payment 100, 90th percentile 564 — payout-book shape |
| Ledger member wallets | 200 | 17,860.00 | 1% of outflow: the ledger is one branch of a much larger book |
Inflows are concentrated in a small set of large senders which also hand over in sequence: 579,163.93 from the payment gateway (Jan – Jul), 370,227.17 from a second address (30 Jul – 19 Aug), 255,750.00 from a third (Jan – Jun), then several more from late August onward.
184,191.53 in — of which 184,050.00 came from the hub in 68 transfers — and 184,049.57 out to 464 counterparties. It retained 141.96 over eight weeks. Outside the ledger's 711 rows it made 441 further payments worth 96,328.40 to 147 addresses, which is the platform's other branches.
Every ledger row on this wallet is exactly 3.00 short. The wallet retains effectively nothing, and TRON resource costs are met by delegated energy and bandwidth visible in its transaction list rather than by deducting from the transfer. The charge is therefore levied on the member and is not a network cost passed through. Across the ledger's 711 TRON rows that is $2,133.
How TRON money becomes BSC money, and how that was established.
Bridge settlements carry no shared identifier on either leg, so the link was tested statistically and then confirmed by identity at both ends. For every BSC inflow of 100 USDT or more into the two funding wallets, we searched the TRON hub's outflows for a preceding transfer whose value exceeded it by a plausible service fee, within a bounded window.
| Test | Matches | Parameters |
|---|---|---|
| Loose | 79 of 140 | ≤ 6 hours, ratio 0.95 – 1.0005 |
| Tight | 53 of 140 | ≤ 3 hours, ratio 0.99 – 1.00, nearest match only |
| Null control A | 5 | BSC timestamps shifted +30 days |
| Null control B | 5 | BSC timestamps shifted −17 days |
The matched pairs are not scattered: each BSC recipient corresponds to a particular TRON destination at a consistent fee.
| BSC leg receives from | TRON leg sent to | Pairs | Implied fee |
|---|---|---|---|
| Bridgers contract | Crossing wallet | 13 | 0.508% |
| Bridgers contract | Service deposit address | 7 | 0.200% |
| Bridgers token contract | Service deposit address | 26 | 0.200% |
| Unlabelled BSC address | Crossing wallet | 5 | 0.755% |
| HOT Bridge treasury | Crossing wallet | 1 | 0.531% |
One pair was opened end to end. On 25 August at 16:51:39 UTC the hub sent 10,000 USDT to the crossing wallet (f5e3e264a86fb06732deb3fb2b50e29873e99eb1588fbc9a0996655e94d81b58), a plain transfer(address,uint256) with no memo. At 17:00:09 UTC, eight minutes later, 9,946.87 BSC-USD arrived at the funding wallet from an address BscScan labels HOT Bridge: Treasury (0xaad1ca96f91154f5e2dd39e18541950644d89b6a83f3f9c44d647b9d5bb07aa3), signed by the bridge's own relayer.
The crossing wallet's own export then closes the loop structurally: created 16 August 2026, four inbound counterparties only, 395,026.91 in and 391,791.20 out, of which 276,800 goes directly into the Bridgers contract on TRON. A shared service address would show hundreds of inbound counterparties; four is an operator wallet.
Why no deposit address exists, and where the record actually lives.
The hub's largest funder carries TronScan's public tag Heleket Hot Wallet 2. It operates at the scale of shared infrastructure: 1,269,652 transactions, 2,272,569 transfers, 2,070,000 TRX staked, with counterparty panels showing tens of millions moving across more than a hundred accounts on each side.
What Heleket is. By its own description it is a crypto payment gateway: a merchant integrates it into a website, app or Telegram bot, the gateway issues the customer an invoice, watches the chain for the incoming funds, reports the payment status back to the merchant's system, and credits the merchant's balance, which the merchant then withdraws to a wallet of their choosing. Published fees start at 0.4%. Merchant sign-up is by email address, and trade-press coverage describes basic onboarding as requiring no identity verification. These are the operator's own published claims and third-party write-ups, not findings of ours, and they are recorded here because they determine where the deposit record sits rather than because they establish anything against Heleket.
It settled 579,163.93 USDT to the hub across 209 transfers between 12 January and 30 July 2026. That is a processor paying out to a merchant.
Member deposits are collected by a gateway, not by a wallet. This explains why no MetaTronics deposit address exists on either chain, and it locates the deposit record precisely: in the gateway's systems and the operator's database. Both are obtainable by a regulator or by the processor's own compliance function. Neither is obtainable from a blockchain.
Identification, payouts received, and the $200,000 claim.
The interim report held only a four-character fragment at each end of this address, which matched six addresses in our corpus — five of them poisoning look-alikes. The identification was closed by a video frame the account holder published, showing all 40 hex characters in the platform's own withdrawal form, matching character for character including the EIP-55 capitalisation pattern, with zero differences.
79 payouts, $92,921, across two of his accounts plus one other account paying to the same address. His $1,800 withdrawal in the video is request #10616, paid 4 July 2026 — the earliest withdrawal on that account and one of the 436 rows the operator could not resolve. It was resolved here: hub B paid it at 15:07:24 UTC, seven seconds before the ledger's timestamp.
Full history pulled: 30 November 2022 to 22 September 2026, 874,300.60 USDT in and 864,234.19 out, running $30,000–90,000 a month long before MetaTronics existed. Between registration on 3 March 2026 and the first payout on 4 July the wallet sent 95,480.84 across 63 transfers to 62 addresses, largest single 9,950, and no destination received 20,000 in aggregate. Only one of its 46 outgoing payments in the July–September window went to a ledger member's wallet.
Not corroborated No investment resembling $200,000 left this wallet in the relevant window. Not excluded A deposit from another wallet, from an exchange account, or on an unexamined chain.
Ledger row #9256 records a $10,000 payout at 15:25:34 UTC on 4 June 2026. No operator wallet made it. The chain shows 999.99 arriving from Binance: Hot Wallet 11 at 15:20:52 and 8,999.99 from Binance: Hot Wallet 10 at 15:25:39, totalling 9,999.98, five seconds after the ledger's timestamp. Whether the operator paid him by withdrawing from an exchange account, or the row was written against his own withdrawals, is not established.
Why naive exports of these wallets overstate everything.
18,693 of 18,788 inbound rows on the BSC payout wallet — 99.5% — are dust below 0.01 USDT from address-poisoning campaigns, including look-alikes of the branch leader's own wallet. Counterfeit tokens using homoglyph symbols (U5DТ, BEP-20 TOKEN*) appear throughout. Every figure in this audit is filtered to the authentic contract address on each chain:
Of 1,115 outbound USDT rows claiming wallet A as sender, 576 were not signed by wallet A. 573 of those carry zero value — spoofed events on the genuine contract. Only three carry value, 220.33 in total, two of them to a common aggregator router. The interim report's finding of forged outbound events is confirmed, and bounded: no meaningful value left that wallet without its signature.
Nine attributions withdrawn or revised. A report is only as good as the claims it retracts.
The interim report identified eight wallets funding hub B and paying the branch leader around $114,000. Public explorer labels on his wallet pages identify seven of them as Binance infrastructure — Hot Wallet 10, 11, 12, 13, 16, Binance 51 and Binance Hot Wallet. Four of the interim report's per-funder totals match these addresses' inbound totals closely. The money was the leader withdrawing from his own exchange accounts.
One address carried as a hub B funder is HOT Bridge: Treasury. Another, carried as the largest unexamined counterparty at 183,409, is a verified Bridgers1.1 contract tagged as a bridge. Both tags are withdrawn.
The interim report described roughly $4,000 through wallet A, from an export ending 10 July. It went on to fund 193,480 of payouts and pay 277 counterparties.
Every withdrawn attribution originated in amount-and-time matching without confirming the address itself — the same method the operator's ledger uses for its level-2 rows. The lesson applies to both: a matching amount at a matching time identifies a transfer, not a party.
None of the above establishes intent, ownership of any address by any individual, or that any offence has been committed. The absence of trading in the examined wallets does not exclude trading inside a centralised exchange account, which no blockchain export can see.
Tag and full address together, every time. Addresses are never shown truncated.
SHA-256 of the primary sources, so any figure can be traced to the file it came from.
| File | Rows | SHA-256 |
|---|---|---|
| Operator withdrawal ledger (XLSX), 21 Sep 2026 snapshot | 4,953 | 8645b4bad2ca69ce4a12d38d9f5c5cdbbf5b380c483a41b688eeef0d324bcb5d |
| Interim report (DOCX), 3 Aug 2026 | — | fdbf3579facbec38420f76784c49f0acb9517a0c48622d2b98a2ec33325f9b2b |
| Investigation handover, 22 Sep 2026 | — | a9f5429daba5da301933ead09855c596227ce206bfc221bbdc3f4d8a99dae995 |
| Video frame confirming the leader's wallet | — | d987bd8c6228cc5184513c332f53d6e91336db3519ba064d694ae39e51d8f275 |
| TRON hub transfers export | 3,948 | b19fc458ceed64e639e6eb5ec478b57f028a49220101f6ce0fc73a8d00b7b003 |
The BscScan exports were pulled as ten windowed files for the payout wallet, 39 pages for the branch leader's wallet, and single files for each funding wallet; the TronScan exports as one file per account. All were re-hashed at the point of use. Where two exports overlap, they were compared row by row in both directions before merging: three overlapping spans matched exactly, with no rows present in one file and absent from the other.
Every check that could have failed, and what it returned.
| Test | Purpose | Result |
|---|---|---|
| EIP-55 checksum, with self-test | Detect altered or mistyped BSC addresses | All valid; a deliberately altered copy was rejected |
| TRON Base58Check | Same, for TRON | All valid; altered copy rejected |
| Collision check on first-6 / last-6 | Detect look-alike addresses before tagging | 0 groups across 5,058 addresses; a synthetic collision pair was detected |
| Fabricated-hash control | Confirm the reconciliation can fail | 0 matches |
| Shuffled-amount control | Confirm level-3 resolution is not coincidence | 0 matches |
| Time-shifted controls (+30d, −17d) | Confirm bridge pairing is not coincidence | 5 matches each, against 53 tight and 79 loose |
| Export overlap comparison | Detect filter drift between pulls | 3 spans, identical in both directions |
| Row-count cap detection | Detect silent truncation at 5,000 rows | 2 files caught and re-pulled; gaps of 50.8 h and 71.7 h closed |
| Explorer hyperlink vs hash column | Detect internal inconsistency in the ledger | 4,517 of 4,517 consistent |
Screen captures referenced in the sections above, retained for the record.