{"id":"detector.drain_pattern.v2","title":"Drain-shaped payment, with the balance it took","unit":"detections","chain_set":"eip155:8453 (Base)","window":"payments in the last 30 days","definition":"A counted payment at least five times the agent's previous largest, at least $250, to an address the agent had never paid, after at least three earlier counted payments: the unchanged v1 rule. New in v2, every detection carries a balance reading: what the paying wallet held in that stablecoin at the block before the payment, and the fraction of it the payment took.","method":"balanceOf at block minus one through an archive-capable RPC, read once per detection and stored on it. A wallet funded and emptied inside one block is read as emptied. The fraction is evidence beside the rule; it does not filter detections yet.","excludes":["Routing hops and payments from before registration, as in v1."],"does_not_assert":["That a payment which emptied the wallet was a theft. On synthetic data with known answers the fraction separated every planted drain from every one-off purchase; on the live ledger 39 of the 47 drain-shaped payments since February took 80 to 100 percent of the balance. Each detection says what was seen and leaves the verdict to the reader."],"source":"AFG-Pulse incident detectors, Base archive RPC","since":"2026-10-11","url":"https://agenticfinancegraph.com/def/detector.drain_pattern.v2","ladder":"https://agenticfinancegraph.com/ai-agent-liveness-methodology-l0-l9-ladder","license":"https://creativecommons.org/licenses/by/4.0/","attribution":"Agentic Finance Graph — https://agenticfinancegraph.com"}