Agentic Finance Graph

Home/Research/Slow-drain windows

Working note · 11 October 2026

Forty-four windows, read one by one

A candidate rule for slow drains opens 44 windows on the live ledger. Before it detects anything, each window gets four signals and a label, and the two that look like drains get their receipts read. The result is a rule with an honest name.

Agentic Finance Graph · Published 2026-10-11 · Automatic pass 11 Oct 2026 · receipts read 11 Oct 2026 · not a detection

44windows the dominant-share rule opens on the live ledger, all time
23service payments: the payee is paid by many agents
14ambiguous: a stranger address, but the agent kept paying others
5single-payer contracts, most likely the agent's own positions
2drain candidates: a stranger took most of the outflow and the agent never paid again

Automatic pass over the ledger on 11 October 2026. A label is a reading aid, not a verdict, and nothing on this page is in the incident log. The rule itself (slowDrainsDominant) is a candidate under measurement, not a live detector; its synthetic record is in the generator repository.

What a window is

The candidate rule asks, for every agent and every payee it had never paid before: did the agent, within 72 hours of that first payment, pay this new address at least $250, at least five times its previous largest payment, in two or more payments of varying size, and did that address take at least 80% of everything the agent paid in those 72 hours? Each row in the table below is one such window. Four signals were then read from the ledger for each: how many agents ever paid the payee, whether the payee is a contract or a plain address (EOA), how many counted payments the agent made to anyone else after the window, and the date of its last payment. The label follows from them.

The two drain candidates, read at receipt level

For both, the payee's own stablecoin movements in the 48 hours after the last payment were read from the chain on 11 October (Transfer logs of USDC and USDT, the payee's code and balance, the agent wallet's balance).

Window 16: agent #57254 → 0xe3ad36b2…28f4, 18 September 2026

Two payments, $955.81 in USDT at 20:55 UTC and $329.90 in USDC at 22:48, to a plain address no other agent had paid. The address forwarded every dollar it held, $1,432.90 including $147 from one other sender, to a contract 0x337685fd…c3e2 (8,840 bytes of code, paid by 106 agents in our book, $3.19M passed through it in those same 48 hours), the USDT within two hours of arriving and the USDC after it. Both the payee and the agent wallet hold nothing now. The agent has not paid anyone since 19 September.

Window 21: agent #45978 → 0x424b266c…c2a1, 11 September 2026

A $2 payment at 07:34 UTC, then $933.10 at 07:47, both in USDC, sent through a relayer (the agent is a smart account), to a plain address nothing else has ever touched. Three minutes after the second payment the address forwarded $935.10 to 0x6dcbce46…4467, a plain address that moved $69.1M in the following 48 hours: an exchange-scale hot wallet. The payee holds nothing now, and so does the agent wallet. The agent has not paid anyone since.

Reading. Both have the shape of a withdrawal through a fresh deposit address into a high-throughput venue: a test amount, the full amount minutes later, everything forwarded at once, silence after. That is what a person cashing out through an exchange deposit address looks like, and it is also what a careful thief does with a stolen key. The chain does not say which. So the rule this reading feeds is not a theft detector. Its honest name is drain, wallet abandoned: the wallet was emptied to a fresh address and the operator never came back. It catches exits, legitimate or not, and must be worded that way wherever it is published.

What the two cases add to the queue: the second-hop addresses, a contract paid by 106 agents and a hot wallet moving $69M in two days, are unlabelled in our book. Naming the venues (from public explorer tags, not guesses) would turn "a high-throughput venue" into a fact, and that enrichment is next.

All forty-four windows

"payee paid by" is the number of agents that ever paid the payee; "kind" is contract (with its code size) or EOA; "paid others after" is the agent's counted payments to other payees after the 72-hour window. The chip is the automatic label; the line under it says why.

service: paid by ten or more agents, or labelledambiguous: a stranger address, but the agent kept paying othersown deployment?: a contract with a single payerdrain candidate: a stranger address and the agent never paid anyone again

#first paymentagentpayee72 h sumpaymentspayee paid bykindpaid others afteragent last paymentautomatic label
1 2026-03-31 #37859 L7 0x1c4a802f… $281,435 3 340 contract · 170 B 372 2026-10-11 service labelled Wasabi vault (WasabiVaultRecoveryV1)
2 2026-03-30 #37859 L7 0xb98c948c… $192,400 34 602 contract · 13830 B 308 2026-10-11 service labelled Morpho: General Adapter1
3 2026-02-23 #18793 L8 0x22f5912f… $100,000 2 1 EOA 61 2026-06-27 ambiguous stranger EOA, agent kept paying others (61 later payments)
4 2026-02-25 #14351 L8 0x99a764ec… $22,994 6 1 contract · 45 B 195 2026-09-17 own deployment? single-payer contract (45 bytes)
5 2026-08-31 #19953 L7 0xbce80645… $13,097 3 1 contract · 21478 B 12 2026-10-10 own deployment? single-payer contract (21478 bytes)
6 2026-02-19 #18097 L7 0x59c7c832… $7,300 7 195 contract · 9942 B 0 2026-02-21 service paid by 195 agents
7 2026-07-08 #34768 L9 0x441c575c… $5,669 2 1 EOA 35 2026-10-10 ambiguous stranger EOA, agent kept paying others (35 later payments)
8 2025-09-11 #56881 L9 0x417f55a0… $4,000 4 1 contract · 171 B 505 2026-10-10 own deployment? single-payer contract (171 bytes)
9 2026-06-10 #55078 L7 0xf8820f06… $3,973 2 1 EOA 14 2026-09-18 ambiguous stranger EOA, agent kept paying others (14 later payments)
10 2026-03-22 #57182 L9 0x4cd00e38… $3,150 3 831 contract · 8628 B 1398 2026-10-11 service labelled RelayDepository
11 2026-09-30 #57325 L7 0x69a52a05… $2,045 38 19 contract · 7337 B 2 2026-10-06 service paid by 19 agents
12 2026-04-06 #20880 L7 0xe6151691… $1,750 5 51 contract · 15463 B 95 2026-10-11 service paid by 51 agents
13 2025-08-28 #4055 L7 0xf6d11e94… $1,529 2 1 EOA 25 2026-09-12 ambiguous stranger EOA, agent kept paying others (25 later payments)
14 2026-07-14 #1499 L7 0x6eee4c47… $1,411 3 1 EOA 3 2026-09-25 ambiguous stranger EOA, agent kept paying others (3 later payments)
15 2026-07-21 #56505 L9 0xe1fda61c… $1,305 2 1 EOA 63 2026-10-10 ambiguous stranger EOA, agent kept paying others (63 later payments)
16 2026-09-18 #57254 L7 0xe3ad36b2… $1,286 2 1 EOA 0 2026-09-19 drain candidate stranger EOA, agent never paid anyone again
17 2025-10-09 #56184 L7 0x89c6340b… $1,056 2 499 contract · 8185 B 107 2026-10-10 service labelled LI.FI: Permit2Proxy
18 2025-10-10 #57689 L8 0xe8b5121d… $999 2 1 EOA 68 2026-10-02 ambiguous stranger EOA, agent kept paying others (68 later payments)
19 2026-09-17 #57326 L7 0x8a311d70… $985 38 259 contract · 2227 B 3 2026-10-09 service paid by 259 agents
20 2026-06-29 #56015 L9 0x6a275486… $984 8 89 contract · 22280 B 19 2026-09-30 service labelled Swap router (unverified, takes a fee)
21 2026-09-11 #45978 L7 0x424b266c… $935 2 1 EOA 0 2026-09-11 drain candidate stranger EOA, agent never paid anyone again
22 2026-08-26 #64056 L7 0x5e4bbded… $910 2 1 EOA 10 2026-10-10 ambiguous stranger EOA, agent kept paying others (10 later payments)
23 2026-06-18 #47218 L8 0x820ad908… $900 2 1 EOA 2 2026-10-09 ambiguous stranger EOA, agent kept paying others (2 later payments)
24 2026-03-08 #21142 L7 0xcb3d2a42… $805 3 1 contract · 14558 B 6 2026-06-12 own deployment? single-payer contract (14558 bytes)
25 2026-08-28 #19226 L7 0xe00e4c0e… $666 8 1 EOA, delegated · 23 B 64 2026-10-10 ambiguous stranger EOA, agent kept paying others (64 later payments)
26 2026-09-22 #38464 L7 0x76923cdd… $592 53 21 contract · 1159 B 4 2026-10-01 service paid by 21 agents
27 2026-09-08 #20490 L7 0xa5c1ce36… $550 2 163 contract · 1196 B 3 2026-10-08 service paid by 163 agents
28 2026-09-07 #58025 L9 0x4e392fbf… $550 6 102 contract · 45 B 10 2026-10-06 service paid by 102 agents
29 2026-09-01 #56425 L9 0xee7b81cf… $512 2 13 contract · 45 B 9 2026-10-11 service paid by 13 agents
30 2026-06-12 #55219 L7 0x1231deb6… $500 2 984 contract · 5176 B 0 2026-06-13 service labelled LI.FI: LiFiDiamond
31 2026-02-12 #2085 L7 0x17efdb06… $487 2 1 contract · 61 B 1 2026-02-18 own deployment? single-payer contract (61 bytes)
32 2026-04-19 #56156 L7 0xc10ee903… $483 2 98 contract · 20486 B 155 2026-10-10 service paid by 98 agents
33 2026-02-18 #57630 L7 0x0a2854fb… $397 2 545 contract · 1168 B 35 2026-09-16 service paid by 545 agents
34 2026-04-24 #57795 L9 0x498581ff… $378 2 510 contract · 24009 B 47 2026-09-30 service paid by 510 agents
35 2026-07-29 #56616 L7 0xe2bcdb65… $370 3 17 contract · 4461 B 4 2026-09-16 service paid by 17 agents
36 2026-09-06 #68832 L9 0x8f10b468… $326 4 228 contract · 13529 B 61 2026-10-11 service paid by 228 agents
37 2026-06-27 #56546 L7 0x6a275486… $320 4 89 contract · 22280 B 429 2026-10-10 service labelled Swap router (unverified, takes a fee)
38 2026-03-02 #21988 L7 0x87e34bdf… $308 2 1 EOA 129 2026-09-07 ambiguous stranger EOA, agent kept paying others (129 later payments)
39 2026-08-22 #56675 L7 0xa996d3f1… $306 8 2 EOA 10 2026-09-19 ambiguous two payers, no clear reading
40 2026-09-12 #95528 L7 0x59c7c832… $304 4 195 contract · 9942 B 8 2026-10-10 service paid by 195 agents
41 2026-08-28 #18557 L7 0x337685fd… $297 5 106 contract · 8840 B 11 2026-10-07 service paid by 106 agents
42 2026-03-13 #34171 L9 0x44f892b0… $290 2 1 EOA 20 2026-10-11 ambiguous stranger EOA, agent kept paying others (20 later payments)
43 2026-02-05 #1159 L7 0x4cd00e38… $289 2 831 contract · 8628 B 0 2026-02-05 service labelled RelayDepository
44 2026-02-19 #18014 L8 0x4ea73531… $257 3 1 EOA, delegated · 23 B 11 2026-04-17 ambiguous stranger EOA, agent kept paying others (11 later payments)

Click a row (or tab to it) for the full reading in the panel; Esc closes it.

What this changes, and what it does not

  • Two cheap filters do most of the work. A payee paid by ten or more agents is a service, not a thief; an agent that keeps paying others afterwards was not emptied. On synthetic data the first removes every service false alarm and the second finds every planted abandoned wallet. Together they keep 2 of these 44.
  • Nothing here is a detection. The dominant-share rule stays off the live detector list until the November release, and the two candidates stay unlabelled until the second-hop venues are named from a source we can cite.
  • The half that are service payments are a reminder of what the rule mistakes for a drain: a first subscription or a first escrow deposit also looks like "a new payee took most of the outflow in 72 hours".

Questions people actually ask

Are the two drain candidates thefts?
Unknown, and the page does not claim it. Both show a withdrawal through a fresh deposit address into a high-throughput venue, which is what a person cashing out looks like and also what a thief with a stolen key does. The rule they feed is named for what the chain can show: a wallet emptied to a fresh address and abandoned.
Why are these windows not on the detections page?
Because the rule is a candidate under measurement, not a live detector. It goes live only with the November release, after the synthetic record and this reading, and only under the name 'drain, wallet abandoned'.
What is a dominant-share window?
The 72 hours after an agent first pays a new address, when that address took at least 80% of what the agent paid in the period, in two or more payments of varying size, at least $250 and at least five times the agent's previous largest payment. The rule reads only the ledger; no chain balance is needed.