Joined November 2009
13 Photos and videos
Bizzee P retweeted
Jun 5
pstables.online/#advanced And now im done for a while... What you can do; 1. This shows a mapping, early pDAI distribution from known big wallets, to contracts and wallets. Remarkable enough only 4 wallets. 2. This shows V3 Debts 3. Liquidity pools 4. AMM pools 5. Paths from Pioneer wallets to other wallets contracts 6. You can do a trace to addresses, this is on internal data i extracted and will get bigger overtime, i cannot possibly RPC or API this because of too many requests i will get blocked. 7. The trace stops at a contract, as the data is way too big to go through at those. 8. Wallet exposure, which wallet has which debt (beta) 9. Bridge Collateral 10. Basic info about pDAI token. This took me a while, have fun. If you have suggestions or you want anything added to it which is reasonable, please tell. $pDAI $Pulse $Hex $pStables $pUSDC $pUSDT $PulseX $Pulsechain @yourfriendSOMMI Be sure to use the url as at the top, /#advanced
5
20
87
3,236
🔍 Three forked governance systems on PulseChain. One already captured through an on chain proposal months ago. 107 admin transactions executed since. One 99.99% emptied with 63 million governance tokens freed and only 5 remaining. One sitting one admin call away from full resurrection. The original protocol teams are dormant. Their multisigs haven't moved. The keys belong to Ethereum signers who never showed up on PulseChain. Meanwhile 30 bots are swarming the same Compound leverage loop. Someone else deployed 38 contracts testing the exact same flash loan infrastructure. 🧪 Everything is captured or capturable. Nothing has been activated. The pieces are on the board but nobody has made the move yet. 👀 1$
10
13
111
2,458
Went back digging into the hyUSD contracts. Found something. 🧵 The AssetRegistry is bricked. Every call reverts. The registry contract is dead but the 13 plugin addresses are still in the storage slots underneath. No explorer shows this. You have to know the layout and pull them directly. 🔍 Once you have the 13 addresses you can call into each plugin. Every one wraps a Chainlink price feed. Every feed still returns a real price. The plugins reject it because the timestamp says May 2023. The data is there. The clock is wrong. ⏱️ Nine of thirteen oracles were manually refreshed September 11, 2024. One by one. Calling refresh() on each plugin to check if they could return a valid price. Every one came back DISABLED. That same month, Solo Voter deployed the entire parallel hyUSD system. They tested the old oracles, confirmed they were dead, and built the replacement. 🏗️ Governance to swap all 13 is wide open. 1 second timelock. Quorum of zero. One proposal does it. The only thing missing is collateral worth pricing. The current wrappers hold forked stablecoins no issuer will ever redeem. That changes the moment real collateral enters the system. 🔑 These 13 plugins aren't broken infrastructure. They're pre-wired. Ready to go. 🔌 Every captured protocol hits the same wall. Aave. Compound. Reserve Protocol. All seized. All governed. Same missing piece. No live oracle. No real collateral. The oracle is the skeleton key to all of them. 🔇 Then @NineIronCapital starts walking through L2 bridge mechanics this week and it all connected. Launch an L2 on PulseChain. Validators run oracles. Real collateral in, overcollateralized stablecoins out. Derivatives bridge back to L1 through gateways already controlled. 🔗 The L2 oracle network is the plug. The 13 plugins are the sockets. The forked MakerDAO was never coming back. It doesn't need to. The L2 IS the new MakerDAO. Everything the fork killed gets rebuilt clean on a chain they fully control. ⚡ Three years of L1 capture wasn't building the engine. It was building the landing pad. pDAI stops being a dead fork artifact. It becomes borrowable collateral across a DeFi stack that's already built, already governed, and already waiting. 🫡
18
32
186
5,069
Three bots have been grinding forked stETH every single day since PulseChain launched. 5.9 million transactions over 26 months. Still going right now. 🤖 214 million stETH minted. 96% of the supply since the fork. 📊 In the last 12 hours 1967 deployed a custom contract targeting the same mechanism. Not the same approach. The contract requires a validator bribe paid to the block producer, execution in a precise block number, and full stake limit consumed in a single transaction. That is not accumulation. That looks like atomic coordination. 🧠 Five attempts. Did not execute. Wrong block timing on four. Stake limit off by 0.0025 PLS on one. The contract works. The test is not finished. ⚙️ This mechanism only makes sense if something else needs to happen in the same block so no one can front run. The oracle goes live. stETH gets minted. The basket initializes. All in one block. Or something else entirely. You do not test that on the real operation. 🔥 Nobody grinds 5.9 million transactions for a $31 Curve pool. The exit has never looked like Curve. 💀 The clean Reserve Protocol system on PulseChain has 13 oracle plugins. All unpriced. stETH is already registered. It may not be the only backing. It may still be the key.🔑 What this means: someone has been pre-positioning in the one PLS-backed asset that is already registered in the new system since day one. 1967 is not accumulating. They are testing infrastructure for something that cannot be seen coming. The system is loaded. The oracles are the missing piece. When one gets written the sequence may already be in motion. 👁️ 1967's nonce after the attempts: 3069. 👀 1$
23
29
226
8,419
Update on the zkSync Lite drain. Bridge is basically empty. 🧵 Yesterday they pulled 30 pWBTC and submitted 45 Merkle proofs in 8 minutes. Proving phase. Testing each exit before committing. In the last hour they came back and cashed in the rest: 275,044 pUSDT 86,822 pUSDC 3,788,362 ZKS 179,876 TRIBE 64,265,764 SHIB 608 AAVE 💰 1967 is the ONLY wallet to ever interact with this bridge on PulseChain. Three years sitting untouched. Why. Merkle proofs require the full zkSync L2 state tree from the exact block PulseChain forked. That data isn't public. Someone had to reconstruct the entire L2 ledger to generate valid proofs for each token and account. Serious engineering. 🧠 Bridge balance: dust. Everything else gone. 🧹
23
29
185
8,178
Ok @TurntSalty now I get it. 🧠 RH in 2020: "tail end risk that if the system fails, you get the overcollateralized ETH, which in theory is worth more than the DAI's notional value. Thus EV." He understood exactly what MakerDAO's shutdown module does. If the system cages properly, DAI holders redeem for overcollateralized collateral. On Ethereum that's ETH at 150% ratios. On PulseChain that's WETH which IS PLS, 1:1. 🔁 Now think about what happens if PulseChain reprices. All that forked collateral sitting in CDPs suddenly has real dollar value. And the End module's redemption flow (pack, cash) would let ANY pDAI holder claim their share. 💰 44 billion pDAI. All of it with a claim on overcollateralized PLS. Uncontrolled distribution to whoever holds the token. 😳 So they killed it. 🔪 Cattie caged the Vat directly, bypassing the End module. ESM was loaded with 300K pMKR but fire() was never completed. Governance was bricked. The redemption flow can never execute. Collateral is trapped in CDPs with no claim path. 🔒 RH said "the ESM doesn't even do what everyone thinks it does lol." He's right. People thought the ESM was an attack. It was a lock. Prevent the overcollateralization payout from going to random holders. 🔐 Then they build a new system. Reserve Protocol. Fresh contracts. Captured governance. Solo voter with a 1 second timelock. pDAI already registered as collateral. Basket waiting to be configured. OA wallet ready to capitalize. 🏗️ Old MakerDAO: overcollateralized PLS claimable by anyone. Liability. ❌ New Reserve Protocol: controlled collateral, controlled governance, controlled peg. Asset. ✅ MakerDAO wasn't killed because it was broken. It was killed because it worked too well. 🧱 TL;DR: MakerDAO has a built in refund button. If the system shuts down, your DAI gets you back more collateral than it's worth. On PulseChain that collateral is PLS. If PLS moons, that refund becomes massive. They disabled the refund button and are building a new system where they control who gets what. 🫡 Receipts 🧾 hyUSD Governor (25 proposals, all from solo voter): otter.pulsechain.com/address… pDAI registered in hyUSD AssetRegistry: otter.pulsechain.com/address… Pioneer 1967 funded solo voter 48Fc (20K PLS): otter.pulsechain.com/address…

24
26
175
5,655
This is happening right now. The zkSync Lite bridge on PulseChain is being emptied. 🚨 Two days ago a wallet in the 1967 pioneer cluster deposited 1 PLS into the bridge and called fullExit three times. Nothing moved. zkSync Lite needs an active validator to process exits and nobody is running one on PulseChain. Today they came back and triggered exodus mode. That's the nuclear option built into every zkSync Lite deployment. Once activated, the validator requirement disappears. Anyone can withdraw by proving their balance in the last verified state. ☢️ 55 exit calls and counting. Nonce still climbing. The WBTC is already gone. 275K USDT, 87K USDC, 608 AAVE still in the bridge. 🏧 On Arbitrum they captured the rollup validators and processed 66 Outbox withdrawals. On zkSync they didn't bother running the chain. They proved it stopped running and triggered the escape hatch instead. Different technique. Same result. 🧠 What this means: every forked L2 bridge on PulseChain is a target. Arbitrum is already empty. zkSync is in progress. Optimism and Polygon bridges are next. The pioneer cluster is systematically collecting every piece of stranded value across every bridge that stopped running after the fork. 🗺️ Third bridge in the crosshairs. Not slowing down. 🧱 Receipts: 🧾 triggerExodusIfNeeded: otter.pulsechain.com/tx/0x9b… First exit: otter.pulsechain.com/tx/0xb4… withdrawERC20: otter.pulsechain.com/tx/0xe4… Original recon (1 PLS deposit): otter.pulsechain.com/tx/0xa0… zkSync Lite proxy: otter.pulsechain.com/address…

25
30
213
13,743
Update: checked the remaining forked bridges on PulseChain. 🔍 Polygon bridge: 244K USDC, 59K USDT, 1.5M pDAI. Admin is the Polygon team multisig. No escape hatch. Locked. 🔒 Optimism bridge: 371M USDC, 71.5M USDT, 1,459 WBTC, 62K AAVE. Optimism Foundation Safe, 5 of 7 multisig. No exodus mode, no capturable validators. Locked. 🔒 The pioneer cluster can only drain bridges with on-chain bypass mechanisms. zkSync had exodus mode. Arbitrum had a capturable validator set. Polygon and Optimism have neither. Two bridges emptied. Two bridges untouchable. For now. Worth noting: the original Ethereum teams still hold the multisig keys. Same private keys work on PulseChain. Right now there's zero incentive to coordinate 5 signatures for worthless forked tokens. But if those tokens ever reprice, money on the table wakes people up. 👀 Two bridges the pioneers can't touch. Two bridges nobody else cares about yet. 🧱
3
37
1,312
🔓 Reserve Protocol on PulseChain has a new owner. Sort of. Someone has been upgrading governance contracts into universal execution shells. One is already done. The new implementation lets whoever controls it make arbitrary calls as that contract. No access control. ❌ A second attempt failed publicly. The target contract's admin was never set, permanently locking it. The proposed upgrade also wasn't compatible with the proxy standard. Dead on arrival. But that wasn't the only contract available. Three more proxies are still upgradeable. One of them holds the OWNER role over the forked eUSD system. Collateral baskets, minting, revenue distribution, role management. All of it. 🔗 The governance voter behind this received 20,000 PLS from a wallet ending in 1967, the same builder wallet tied to the Compound capture, the Arbitrum bridge drain, and the Aave lending pool implementation swap. One vote. One wallet. 💡 Why does this matter? The forked eUSD system is one of the few stablecoin protocols on PulseChain with upgradeable governance still intact. Full control means the ability to reconfigure collateral, set minting conditions, and redirect revenue. Not a new protocol. A repurposed one. ⚙️ Someone with 25,000 transactions is methodically converting forked DeFi contracts into programmable tools. Not building new infrastructure. Repurposing what's already there. One governance vote at a time. RECEIPTS: Successful lockpick (hyusdRSR converted to multiCall shell): otter.pulsechain.com/address… Implementation (4.8KB, multiCall upgradeTo, zero access control): otter.pulsechain.com/address… Solo voter (25,376 nonces): otter.pulsechain.com/address… Failed proposal on bricked proxy (admin_slot = 0x0): otter.pulsechain.com/address… eUSD Main (OWNER role, upgradeable): otter.pulsechain.com/address… eUSD Governor Alexios: otter.pulsechain.com/address… hyUSD Governor Alexios: otter.pulsechain.com/address…

7
11
87
2,524
Corrected receipts. Some of the proxy addresses don't render on PulseChain explorers because they were forked at genesis with no creation tx. Here are the ones that work: hyUSD Governor Alexios (proposals votes): otter.pulsechain.com/address… eUSD Governor Alexios: otter.pulsechain.com/address… Solo voter (25,376 nonces): otter.pulsechain.com/address… eUSD Main (OWNER role): otter.pulsechain.com/address… The lockpicked proxy (0x7db3c5) and multiCall implementation (0xe83486) are on-chain but invisible to explorers. Verify with eth_getCode via RPC.

3
32
688
🧵 A cluster of pioneer wallets emptied the forked Arbitrum bridge on PulseChain. The Arbitrum One rollup contracts were forked onto PulseChain with all their state in May 2023. Same addresses as Ethereum. The validator whitelist was disabled. Pioneer wallets staked in and started confirming nodes. Then they executed 66 Outbox withdrawal transactions and pulled every token locked in the bridge down to zero. The primary executors: c28a (27 txs), 1967 (25 txs), 0000 (3 txs), 5996 (1 tx). If you've been tracking pioneer wallets, you recognize these. I checked 19 major tokens. DAI, USDC, USDT, WETH, WBTC, UNI, CRV, AAVE, LINK, COMP, MKR, LDO, rETH, PEPE, GRT, PENDLE, YFI, GNO, FRAX. All empty. 50 token contracts total. Gateway balance: zero. The most recent validator transaction was May 13, 2026. These tokens are worth almost nothing on PulseX. So why take them. 🔹 3.2M pCRV 🔹 885K pUNI 🔹 6.3K pAAVE 🔹 644K pLDO 🔹 459 pCOMP 🔹 91 pMKR 🔹 17.9M pPENDLE 🔹 544K pSUSHI 🔹 20.7K pRPL 🔹 7.3K pENS 🔹 2.5K prETH Governance tokens. Every single one. The same wallet cluster that used 71,569 pCOMP to take over Compound via Timelock. The same cluster connected to pMKR governance. The same cluster locking veCRV for 4 years. The same cluster that already captured pARB proxy upgrades and is running liquidation infrastructure across Gearbox, Compound, and MakerDAO. Nobody takes worthless tokens from a dead bridge unless they're not worthless to the person taking them. Every forked protocol on PulseChain has a governance token. Somebody has been collecting all of them. 🫡 📋 Receipts: RollupProxy (PulseChain): scan.pulsechain.com/address/… L1ERC20Gateway (empty): scan.pulsechain.com/address/… Outbox: scan.pulsechain.com/address/… First drain tx (Aug 14 2024): scan.pulsechain.com/tx/0xe20… Final batch tx (Sept 21 2025): scan.pulsechain.com/tx/0x002… Latest validator tx (May 13 2026): scan.pulsechain.com/tx/0xba1…

28
34
201
9,624
⏺ 🚨 The protocols everyone assumes are dead on PulseChain aren't dead. They've been captured. Was digging through forked protocols today and found someone took over Aave V2. The Guardian multisig became a single key EOA on PulseChain. 51 days post fork, they replaced the entire LendingPool with a 3 function drain contract. Sweep tokens, burn aTokens, empty initialize. 527 bytes. The whole lending protocol, gone. Why would someone do this? If you don't take the keys, someone else will. Every forked multisig is an open door. You either walk through it and secure the protocol, or you leave it for someone with worse intentions. Draining Aave's remaining deposits and locking down the implementation is arguably the responsible move on a fork chain where the original team will never show up. 🧵 Here's how it works. When PulseChain forked Ethereum, every Gnosis Safe multisig became a single key EOA. The Safe proxy infrastructure didn't carry over. What required 5 of 10 signers on Ethereum only needs ONE signer on PulseChain. One key from the original multisig gets you full control over everything that multisig governed. 👀 @NineIronCapital just caught the same pattern on Reserve Protocol. ERC1967 proxy upgrade, forked admin key, full governance takeover in 5 blocks. Compound's Timelock admin is an EOA. Uniswap governance has quorum=0. Yearn vaults still hold 44M pDAI. 🔑 The "dead" protocol graveyard is a key factory. And the keys are already being used.
8
20
172
5,866
Update: not every Gnosis Safe collapsed to EOA. Some carried over intact (Alchemix: threshold=3, Yearn governance: threshold=6). The Aave Guardian Safe specifically has 0 bytes of code on PulseChain, which is why it was exploitable. The vulnerability is real but not universal. Digging into what determines which Safes survived and which didn't.
15
685