Log in
For business
KYT office
Compliance solution to monitor risks, detect sanctions and ensure AML rules.
KYT office
Compliance solution to monitor risks, detect sanctions and ensure AML rules.
AML certification
How industry players can get up-to-date knowledge and professional certification.
AML certification
How industry players can get up-to-date knowledge and professional certification.
Comprehensive transaction analytics that helps to build graphs and trace funds.
Graph
Travel rule
(soon)
For personal use
Telegram bot
Bot for checking crypto for risks, providing AML reports.
Telegram bot
Bot for checking crypto for risks, providing AML reports.
Crypto recovery
Services are focused on tracking
and recovering crypto assets.
Сrypto recovery
Services are focused on tracking
and recovery crypto assets.
Docs and reports
All types of documents related
to cryptocurrency.
Docs and reports
All types of documents related
to cryptocurrency.
Portfolio tracker
Information about all assets and risk assessment in one place.
Portfolio tracker
Information about all assets and risk assessment in one place.
AML checks
Сhecking wallets and transactions
for illicit funds.
AML checks
Сhecking wallets and transactions
for illicit funds.
ES
FR
中文
Вход
AML-сертификация
Актуальные знания в области AML/KYT от ведущих экспертов отрасли.
AML-сертификация
Актуальные знания в области AML/KYT от ведущих экспертов отрасли.
Graph
Визуализация перемещения активов
и связей между кошельками.
Graph
Визуализация перемещения активов
и связей между кошельками.
KYT Office
Мониторинг транзакций и кошельков для вашего отдела комплаенса.
KYT Office
Мониторинг транзакций и кошельков для вашего отдела комплаенса.
Для себя
Для Бизнеса
Travel rule
(Cкоро)
Телеграм-бот
Бот для проверки кошельков и транзакций с выдачей отчётов.
Телеграм-бот
Бот для проверки кошельков и транзакций с выдачей отчётов.
Возврат средств
Услуги по отслеживанию и возврату украденных криптоактивов.
Возврат средств
Услуги по отслеживанию и возврату украденных криптоактивов.
AML-проверки
Проверка кошельков и транзакций на наличие "грязной" криптовалюты.
AML-проверки
Проверка кошельков и транзакций на наличие "грязной" криптовалюты.
Портфолио трекер
Информация о всех активах и оценка рисков в одном месте.
Портфолио трекер
Информация о всех активах и оценка рисков в одном месте.
Отчёты
Все типы документов связанные
с криптовалютой.
Отчёты
Все типы документов связанные
с криптовалютой.
PRIVATE
Government
Financial institutions
Exchanges
PSP's
Wallets
Gambling platforms
Investment platforms
Stablecoin issuers
Investigators
Regulators
Law enforcement
Для бизнеса
Госсектор
Финансовые организации
Биржи
Платежные провайдеры
Кошельки
Игровые платформы
Инвестиционные платформы
Эмитенты стейблкоинов
Расследователи
Регуляторы
Правоохранительные органы
ES
FR
中文
23.09.2026

Why Hunter Biden's LAPTOP Token Followed TRUMP and MELANIA Down

What do prominent Democrats and Republicans have in common? Tokens bearing their names have lost more than 99% of their peak value. Hunter Biden, the son of former U.S. President Joe Biden, is the latest to join that club. As of late September 2026, his cryptocurrency, LAPTOP, was trading 99.98% below its September 9 peak of $401.12. Donald Trump's TRUMP and MELANIA, associated with the wife of the current U.S. president, have suffered similar declines.
LAPTOP price chart. Source: TradingView

Investors have had months to make up their minds about TRUMP and MELANIA, both of which have traded more than 90% below their highs. Some still hold out hope for LAPTOP. BitOK analysts examined whether the project has any prospects.

This investigation was conducted using BitOK Graph.


Contents:

  • LAPTOP at a glance
  • How the billion tokens were allocated
  • Who can authorize transfers
  • Who received large allocations before launch
  • Why 40 million tokens changed recipients
  • What happened in the market after the announcement
  • Who decides the outcome
  • Who funds the project and who may receive its profits
  • What the technical review found
  • The unanswered questions
  • Conclusions
  • How we conducted the review
  • Addresses for verification

LAPTOP at a glance

LAPTOP is a digital token whose project documents name Hunter Biden as a co-founder. Its organizers promise airdrops, charitable distributions and the removal of some tokens from circulation based on political and market events. Yet before the announced launch, nearly 97.7% of the supply sat in seven Safe wallets controlled by the same set of owner addresses. BitOK analysts compared project documents with on-chain transactions to determine who can technically move the tokens, how the airdrop terms changed and what remains undisclosed about the beneficiaries of the project's profits.

The name LAPTOP refers to Hunter Biden's laptop. In October 2020, ahead of the U.S. presidential election, news outlets published reports based on messages allegedly recovered from a computer left at a repair shop in Delaware. The reports concerned Hunter's business ties and his associates' alleged access to Joe Biden. The story sparked political controversy and disputes over the authenticity of the material; Biden's campaign denied the meeting described in the reporting.

On September 7, 2026, Hunter publicly announced a crypto project whose name alluded to that story. The project centers on the LAPTOP token.

By the time of the announcement, the entire one-billion-token supply already existed. The tokens had been minted more than four months earlier and subsequently distributed among several wallets.

According to the documents, the project involves a British Virgin Islands company, a Cayman Islands foundation, an unnamed private lender and a separate company that may receive residual profits.

BitOK analysts calculated that, as of September 8, 976,974,090 LAPTOP, or 97.697409% of the total supply, were held in seven Safe smart contract wallets. All seven had the same owner addresses and the same threshold for authorizing transfers.

This investigation examines the network as of September 8, 2026, at 03:32:29 UTC, one day before the announced September 9 launch.

How the billion tokens were allocated

The official LAPTOP smart contract was deployed on April 27, 2026, on Base, a network built on Ethereum. Its address appears on the project website.

The entire supply first went to a treasury Safe. More than four months passed between contract deployment and the public announcement. A lengthy preparation period alone does not establish that private sales occurred.

By September 1, two allocations of 100 million LAPTOP each had been transferred from the treasury into other wallets. In each case, a test transfer of one token preceded a transfer of 99,999,999. The remaining 800 million were distributed across five addresses:

  • two wallets received 300 million each;
  • one received 100 million;
  • two more received 50 million each.
Five one-token test transfers plus the main transfer of 799,999,995 LAPTOP add up to exactly 800 million. At the time of the review, the original wallet held no LAPTOP. BitOK analysts reconciled the distribution against Transfer events, the contract records used to log token movements. The full one-billion-token supply was accounted for.

The allocation sizes match the published distribution plan:

Purpose under project documents

LAPTOP tokens

Share of total supply

Founders

300 million

30%

Political and market events

300 million

30%

First airdrop

100 million

10%

Future airdrop

100 million

10%

Trading liquidity

100 million

10%

Charity

50 million

5%

Foundation treasury

50 million

5%

Matching totals, however, do not identify the purpose of a particular address. The two 300-million-token wallets could correspond to the founders and the event allocation, but it is not yet possible to tell which is which. The same uncertainty applies to the two 50-million-token wallets and the three 100-million-token wallets.

One of the 100-million-token wallets can be linked to preparations for trading. Transactions through it match the disclosed token loan to firms supporting market liquidity. Definitively assigning every address to a category would require confirmation from the issuer, the company that issues the token.

The claim that 35% of the tokens would be unlocked at launch needs its own explanation. Unlocking removes restrictions on an allocation; it does not show that independent buyers have received the tokens. Actual distribution must be assessed through transfers and the authority of the recipients.

Who can authorize transfers

Each of the seven Safes holding large balances has a two-of-three threshold: a transaction requires approval from two of its three owner addresses. Each approval is made with a cryptographic key.

The owner addresses are identical across all seven wallets. The original treasury and the wallet that received ownership of the LAPTOP smart contract use the same configuration.

The identities of the keyholders and their contractual relationships have not been established publicly. The number of addresses therefore does not tell us how many independent parties control them.

For some allocations, the documents describe custody by Coinbase Custody, a digital-asset custodian, and restrictions on token transfers. BitOK analysts did not, however, identify an owner address independently verified as belonging to Coinbase Custody.

That observation does not establish that the company is uninvolved in custody. Internal approval processes and contractual obligations may operate off-chain. But without a list of the addresses it services and the rules for releasing tokens from custody, the promised restrictions cannot be tied to specific wallets and verified.

The documents assign the tokens to different purposes. Technically, the bulk of the supply is controlled by the same set of owner addresses. The missing link is verified information about who holds the keys and what restrictions bind them.

Who received large allocations before launch

BitOK analysts traced several large transfers before the snapshot. Allocations of 15.5 million, 5 million and 1.5 million LAPTOP came from the same Safe. Another 1.025 million came from a different 100-million-token wallet. The documents and transaction history suggest possible purposes for some of these transfers; others remain unexplained.

15.5 million LAPTOP: a possible link to market maker GSR. The tokens passed through an intermediary address before reaching a recipient that service labels and funding links tentatively place within GSR's operational network. GSR provides liquidity in crypto markets.

5 million LAPTOP: a possible allocation to a second market maker, G20. A different address received 1.346 tokens, followed by 4,999,998.654. Together with the first allocation, that makes 20.5 million LAPTOP, the aggregate token loan to GSR and G20 disclosed in the project's terms.

Market makers post bids and offers to help other traders execute transactions. Loaned tokens can be used for that work. The matching total makes the second address a candidate for G20's allocation, but does not establish who owns it.

1.5 million LAPTOP: a possible operating partner. The tokens went to an existing Safe with a history of connections to token distribution infrastructure, including Merkl, a rewards distribution service, and addresses labeled by analytics services as associated with the Aerodrome trading platform. Those links warrant examining a contractor's potential role, but do not establish why the tokens were sent.

1.025 million LAPTOP: purpose unknown. A separate address received the tokens from another 100-million-token wallet. The recipient's past participation in airdrops does not explain the new transfer. There is no basis for identifying it as a particular subscriber, investor or person with inside information.

The totals for the last two allocations include test transfers: the 1.5 million comprises 10 and 1,499,990 LAPTOP, while the 1.025 million comprises 10 and 1,024,990. Looking only at the main transaction would understate each allocation.

Why 40 million tokens changed recipients

The terms of the first free token distribution, or airdrop, changed while the transfers were taking place.

Originally, 100 million LAPTOP were designated for three groups:
  • 20 million for users who lost money on Donald Trump-linked TRUMP;
  • 40 million for Hunter's subscribers on Substack, a publishing and newsletter platform;
  • 40 million for the audience of the Channel 5 media project and journalist Andrew Callaghan.
In the revised document, Channel 5 disappeared from the list and the allocation for Substack subscribers doubled.

Recipients

Original allocation

Revised allocation

Users who lost money on TRUMP

20 million

20 million

Substack subscribers

40 million

80 million

Channel 5 / Andrew Callaghan audience

40 million

Category removed

Total

100 million

100 million

BitOK analysts established the change by comparing two versions of the document. The files have different SHA-256 hashes, digital fingerprints of their contents. A fresh download at 05:24 UTC on September 8 confirmed the revision. The comparison establishes that the terms changed, not that the tokens were distributed. The reviewed sources offered no explanation for the decision.

Users who lost money on TRUMP were allotted 2% of the total LAPTOP supply. It would be incorrect to treat all 20% reserved for the first and future airdrops as compensation for that group. Trading platforms may distribute tokens to users with trading losses at their discretion; the document sets no uniform compensation formula.

There is another discrepancy concerning unclaimed tokens. The terms disclosure calls for them to be burned after a 30-day claim window. Burning removes tokens from available circulation. Section G.13 of the white paper, which describes the project's structure and terms, specifies a different destination: charity.

Participants need to know which rule will apply. Under one, the remaining tokens should become unavailable for further use; under the other, they would move into the charitable allocation.

The claim process itself could not be fully established at the time of the review. The website's code contained the address airdrop.laptoptoken.com, but the link button was disabled. Reviewing the pages, published code, FAQ, terms and sitemap did not reveal the airdrop's executing contract or show how the server authorizes claims with its digital signature.

Without those components, it is not possible to independently verify:
  • how many tokens each participant may claim;
  • how repeat claims are prevented;
  • who can replace the key the server uses to sign authorizations.

What happened in the market after the announcement

On September 7 at 17:03:13 UTC, a Uniswap V3 pool for LAPTOP and USDC was created on Base. Uniswap is a token exchange; a pool is a contract into which participants deposit assets for trading. USDC is a stablecoin designed to track the value of one U.S. dollar.

The pool charged a 1% fee. At creation, 1,000 USDC and no LAPTOP were deposited, a so-called single-sided liquidity position. The buy button on the project website remained disabled. The existence of the pool shows why the absence of a trading pair on a market data aggregator does not prove a lack of trading infrastructure. As of the snapshot, however, no swaps had occurred in this pool.

Uniswap V3 lets liquidity providers specify a price range. When the current price is outside that range, the position is not available for swaps. The positions in this pool were outside the active range.

BitOK analysts reviewed the pool's complete event log from creation through the snapshot block and recorded:
  • five liquidity additions;
  • two reductions of liquidity positions;
  • two withdrawals of proceeds from positions;
  • no swaps between LAPTOP and USDC in either direction.
A total of 3,299.528153 USDC went in, and 999.999998 USDC came back out. The pool retained 2,299.528155 USDC and zero LAPTOP. Liquidity available for swaps at the current price was zero.

One address opened the first position, while another made the subsequent changes. Neither has been shown to be linked to the organizers; anyone can create a public pool.

Even before the pool appeared, addresses began preparing approvals for future transactions. The first was recorded on September 7 at 14:58:09 UTC, just 2 minutes and 57 seconds after Hunter's announcement at 14:55:12 UTC. By September 8 at 03:26:35 UTC, 58 addresses had issued 78 approvals.

Under the Approval mechanism, a wallet owner authorizes a specified contract to spend tokens within a set limit. Approval can be granted in advance, before the wallet receives any tokens. All 58 addresses had zero LAPTOP at the snapshot. In all 78 transactions, the sender was the address granting approval. The token's complete preserved event log contains no earlier events of this kind.

Forty-eight of the 78 approvals went to a single contract. Other approved spenders included Uniswap and Aerodrome trading contracts and Permit2, a token approval management tool.

The shared contract could indicate use of the same trading tool. It does not establish common ownership of the wallets. A review of their funding histories likewise found no verified single source connecting all 58 addresses to LAPTOP's organizers.

The observed activity shows preparations for transactions shortly after the announcement. It does not establish that swaps occurred in the pool under review or that anyone used nonpublic information.

Who decides the outcome

A total of 300 million LAPTOP, or 30% of the supply, is tied to political and market events. Under the project rules, a favorable outcome should send the relevant allocation to a burn address. An unfavorable outcome sends it to a restricted charitable allocation. The amounts assigned to all 30 events add up to exactly 300 million.

Whether this promise can be checked depends on three things:
  • a precise definition of the event;
  • the observation period;
  • the source used to determine the result.
Eighteen events link to Kalshi or Polymarket, platforms where users trade contracts tied to possible event outcomes. The other 12 have no external market.

BitOK analysts checked the linked market data. Even where a link exists, the specific contract must be identified: a single page may contain several deadlines or price thresholds. Several examples illustrate the problem.

Bitcoin: the rule runs to 2029, but the linked markets run to 2026. The project ties 10 million LAPTOP to Bitcoin reaching a new all-time high by September 2029. Yet the data retrieved from the linked Polymarket page contained markets with deadlines in March, June, September and December 2026. No contract matching the required 2029 horizon was identified.

The start of the observation period is also unclear. Without it, there is no unambiguous prior record against which to judge whether a high is new.

Trump's approval rating: 38% is not 37%. LAPTOP's rule requires the rating to fall below 37%. In the linked Kalshi group, the 38% threshold had already resolved, but the 37% contract remained active. The outcome of a neighboring market does not settle the project's condition.

The date in a page URL is not necessarily the deadline for the relevant event. A Kalshi link containing “26JAN” included a separate contract for a law's passage by January 2028. A page about the cabinet grouped completed short-term markets alongside a contract running to January 2027. The deadline cannot be inferred from the link's name alone.

Price thresholds must be checked separately. The rules for the crypto tokens HYPE and ZEC specified $100 and $1,500, respectively. The review used markets for those exact prices, rather than nearby thresholds that had already resolved.

Events concerning mentions by celebrities and some of the price conditions also need a clearer starting date.

If a source is unavailable, an outcome ambiguous or a dispute arises, the documents leave the final decision to Phoenix Veritas Ventures Ltd, LAPTOP's issuer. The fate of some tokens thus depends on a company's decision and subsequent transfer, not solely on an event with an automatically verifiable outcome.

The promised burns also require scrutiny of how they are carried out. A conventional transfer to an inaccessible address may remove tokens from circulation without reducing the total supply recorded by the contract. The evidence would be a specific address and transaction, not a counter on a website.

For cross-chain transfers, “burning” can refer to something else: tokens are destroyed on the source chain and minted on the destination chain. If the same amount is minted, the global supply does not shrink.

Who funds the project and who may receive its profits

LAPTOP's issuer, Phoenix Veritas Ventures Ltd, is registered in the British Virgin Islands. Its GLEIF record, in the international database of legal entity identifiers, lists company number 2204943 and an incorporation date of March 26, 2026.

According to the white paper, the issuer's sole shareholder and corporate director is the Cayman Islands-based Phoenix Veritas Foundation. In other words, the foundation is listed as the company's owner and the legal entity acting as its director. Hunter Biden and Hervé Larren are named as co-founders. The documents do not say how the founders' 300 million tokens are divided between them.

The documents mention a private loan of approximately $1.4 million, but the available information does not establish:
  • who provided the funds;
  • the interest rate;
  • what assets or rights secure repayment;
  • when the loan falls due;
  • whether the lender received additional economic rights.
ETH transfers show activity by technical operators; ETH is used to pay network fees on Base. Those transfers do not reveal where the loan came from.

In the histories of five key operator and owner addresses reviewed by BitOK, analysts found no direct transfer of standard USDC or USDT that could reasonably be linked to the $1.4 million financing. USDT, like USDC, is a dollar-pegged stablecoin. The review covered only those addresses on Base, not bank payments or other blockchains.

A separate provision concerns TTM Media Group LLC. Under the terms disclosure, residual profits may be transferred to this company, which the founders own and control, after operating expenses have been paid.

The founders' potential financial benefit is therefore not limited to selling their token allocation after it unlocks. The documents provide another route for receiving proceeds. No actual payments to TTM were established.

The materials reviewed did not include an original company registration record unambiguously linking the name in the document to a particular entity. A suggestion that it is registered in Wyoming remains unverified. A matching name and registered-agent address are insufficient; a registered agent receives official documents on a company's behalf.

TTM's ownership stakes, payment details and contractual formula for residual profits have not been established. Without the formula, it is impossible to verify which revenue and expenses are counted before funds are transferred.

Another figure deserves scrutiny. The white paper puts the approximate fully diluted valuation of the entire token supply at $50,510 on March 31, 2026, before the official contract was created. This measure is known as FDV. Without a valuation method or details of an underlying transaction, the number cannot be treated as a verified market valuation of the project on that date.

What the technical review found

A code review and a review of financial obligations answer different questions. A functional contract does not establish that airdrops, custody arrangements or payments will be performed as promised.

For the technical review, BitOK compiled LAPTOP's published source code and compared the resulting program with the on-chain contract. The creation code, deployed runtime code and description of available functions matched. The review documented 50 local test scenarios, including 550 reproducible checks using randomly generated inputs.

Within the scope examined, analysts found no critical or high-severity vulnerabilities exploitable by an ordinary user without special privileges.

BitOK analysts also reconstructed the histories of 11 Safe wallets:
  • 238 event records and 79 executed transactions were reviewed;
  • the records were checked against on-chain confirmations;
  • the number of executions was reconciled with each wallet's transaction counter;
  • 49 cryptographic signatures were recovered and 72 approvals made through Safe's preapproval mechanism were analyzed;
  • all 121 authorizations examined matched owner addresses in the reconstructed history.
The wallets were configured using standard Safe components. Reviewing them gave no basis to claim a hidden access mechanism was found. At the snapshot, the 11 wallets also had no identified active auxiliary modules or guard components that could alter the available paths for executing transactions.

The original address that created LAPTOP did, however, retain a separate administrative role. After ownership of the token was transferred to a Safe, the address remained a delegate of LayerZero Endpoint, part of the cross-chain messaging system. A delegate can configure that component. Transferring ownership of the token did not automatically revoke the role.

Analysts confirmed that the role persisted by simulating calls to the live contract without changing its state. It does not itself confer a right to transfer someone else's LAPTOP. At the snapshot, connections to contracts on other chains had not been configured. What was established was additional administrative access, not a demonstrated ability to steal funds.

The security findings did not cover:
  • the airdrop claim application;
  • the custodian's internal procedures;
  • performance of contractual token-vesting schedules.
Regulatory filings are no guarantee either. MiCA is the European Union's regulatory framework for crypto-assets. A project description appearing in the relevant register does not amount to government approval. Naming intended trading venues does not show that those venues have agreed to list the token.

The unanswered questions

At the snapshot, LAPTOP had an official contract, published terms and a traceable transfer history. At the same time, nearly its entire supply was held in wallets with the same owner addresses. The available data do not allow all economic rights or methods for fulfilling the project's promises to be verified.

These are the main unanswered questions investors should consider:
  • Who provided the $1.4 million loan, and what rights did the lender receive?
  • Which company is TTM Media Group LLC, who owns it, and how are the profits payable to it calculated?
  • Which wallets does Coinbase Custody service, and how are the restrictions on each allocation enforced?
  • Why were 40 million LAPTOP reassigned from Channel 5's audience to Substack subscribers?
  • What happens to unclaimed airdrop tokens: are they burned or sent to charity?
  • Why were the 1.5 million and 1.025 million LAPTOP allocations made, and who owns the address tentatively linked to G20?
BitOK's investigation does not establish fraud, personal ownership of unidentified wallets by Hunter Biden or trading on nonpublic information. It does establish that promises are spread across several documents and entities, while technical control over most of the tokens rests with the same set of owner addresses.

Conclusions

The mechanics of the LAPTOP project and its market performance leave little reason for optimism. Technically, there are few apparent problems: the contract matches the published code, no critical vulnerabilities were found, and wallet histories can be reconstructed. But a sound smart contract says nothing about the value of the token itself.

LAPTOP gives holders no stake in a business, access to a service or other practical utility. Its price depends on interest in Hunter Biden's name and promises of airdrops and burns, whose fulfillment largely depends on decisions by the issuer.

Is LAPTOP a scam? The investigation found no direct evidence of fraud. It did not establish that Hunter Biden personally owns unidentified wallets or find evidence of insider trading. Still, the project has several features that should give investors pause:
  • The same set of keys controlled nearly 98% of the supply before launch.
  • The airdrop terms changed without explanation.
  • The documents conflict over what happens to unclaimed tokens.
  • The lender behind the $1.4 million loan is unidentified.
The documents also provide a separate channel for profits to flow to a founders' company. It is more accurate to describe LAPTOP as a highly opaque project than as a proven scam: buyers bear almost all the risk, while the organizers retain control.

Has LAPTOP followed the same path as TRUMP and MELANIA? In price performance, yes, and faster. TRUMP and MELANIA lost value over months. LAPTOP fell 99.98% from its peak in roughly two weeks after launch.

All three projects share a model: a famous name, a burst of early interest, most of the supply allocated to team-linked entities and a gradual release of those tokens. LAPTOP differs in its presentation, with a detailed white paper, a MiCA registration for its disclosures, charitable language and burns linked to political events. Those details create an appearance of planning, but do not change the central problem: the token has no source of demand beyond interest in the name.

Does the project have a future? Short-lived price spikes are possible, perhaps on news of an airdrop, listing or another burn. Sustained growth is harder to envision while large allocations remain controlled by the same set of owner addresses and are gradually unlocked.

Anyone considering LAPTOP should treat it as a speculative memecoin with a high risk of losing the entire investment.

How we conducted the review

BitOK analysts recorded the state of Base at block 51,024,501. A block is a batch of ledger records; its number lets others repeat the review against the same network state. All queries were read-only. The technical identifiers below are supplied to reproduce the results, not because they are needed to follow the main story.

Item

Identifier

LAPTOP contract

0xB095274743941e953c746F9C228DA9c18Bb6ec29

LAPTOP/USDC pool

0x7702411b3893ea4f6ab96c50231cfec65448ab9f

Snapshot block hash

0xba38ee9df361bb0e92632cf4cde2e6a0aa5e674af501b71faceeaee0b751bc1a

Issuer's Legal Entity Identifier (LEI)

98450001A3B1BFFE8455

Ownership history. Repeated queries confirmed the owner addresses, thresholds and Safe software version 1.4.1 across all 11 wallets examined. Analysts checked the addresses of the implementation code and the component that handles wallet calls. Each wallet's setup used SafeToL2Setup, Safe's standard setup component for networks built on Ethereum. The code hashes of this component, SafeL2 (the wallet implementation for Ethereum layer 2 networks), the call handler and MultiSendCallOnly matched Safe's official deployment registry.

Ten batched transactions used MultiSendCallOnly, a component that executes multiple calls in one transaction. All 28 inner calls were ordinary calls to other contracts. None was an internal delegatecall, which executes external code in the calling contract's context. The use of that mechanism for a standard component during initial setup does not itself establish hidden privileges.

A third owner address was added to the nested Safe on April 16, and a fourth on August 28; the threshold remained one approval. After creation, each of five new distribution wallets made one transfer returning 0.001 ETH to the operator. Their transaction counters, or nonces, each stood at one at the snapshot.

Completeness limitation. Events were located with an indexer, a service for searching blockchain records, then checked against responses from a network node through its RPC interface. Matching transaction counters provide additional confirmation of the execution count but cannot rule out a missed record that does not change the counter.

The absence of auxiliary modules says nothing about how keys are held internally. An organization might, for example, use MPC, in which several parties jointly carry out cryptographic operations, or an off-chain approval process.

Different kinds of approval. A Safe transaction's preapproval is called ApproveHash. It differs from an ERC-20 Approval, by which a token holder allows a contract to spend tokens. The 72 Safe approvals and 78 trading approvals therefore cannot be combined into one figure.

Precise event names. Deposits into the pool appear as Mint, reductions of positions as Burn, withdrawals as Collect and trades as Swap. In this log, Burn means reducing a liquidity provider's position; it must not be confused with the promised burning of LAPTOP after an event outcome.

The code review compared creation bytecode (the code that creates the contract), runtime code (the deployed contract's executable code) and the ABI (the description of its callable functions). The 49 recovered signatures used ECDSA, a cryptographic algorithm for verifying transaction authorization. The total supply value mentioned above is obtained from totalSupply(). The ERC-20 standard sets common rules for accounting for and transferring tokens; OFT is a mechanism for tokens operating across chains. These names are included to help readers match the findings to the technical evidence.

Attribution sources. An executed transfer, a term in a document and a hypothesis about an address's owner are treated separately. A service label, a matching amount or a shared provider does not establish the recipient's identity.

Additional evidence. The underlying study lists separate files containing a register of all 30 events, a reconciliation of 19 fund-flow paths, full transaction IDs and checksums for the evidence.

Addresses for verification

Role

Address on Base

Safe that sent 15.5 million, 5 million and 1.5 million LAPTOP

0x8aeaffde02e751c04d96cec90d93f93c50bcc530

Final recipient of 15.5 million; tentatively linked to GSR's operational network

0xe92e65049b3c2ca12806e9567b08895118c5a03f

Recipient of 5 million; possible G20 allocation, not independently verified

0x7dbb9d5a7ebd5957675bfc7598cc17f10823344d

Safe that received 1.5 million; purpose unknown

0x80f7153d9bc853a9bf8bc21f2517c0acee2fdf75

Recipient of 1.025 million; purpose unknown

0x716df284d8b60e06c7d38d818abf664364516d76

Sender of the transaction opening the first pool position

0xfa765ff4b0ae7b4e8902093ac5f08a7af4d76c93

Sender of subsequent position changes

0x955d4a6af54318b4e56220ecdb58ba71e9890f23

Address granted 48 LAPTOP spending approvals

0x00000000e91fc5bad977c0cc4ad60557c06886a2

Support
Get it

To inquire about our plans, click here

Try BitOK for free