Key Takeaways
- Tradewiz users lost about $459K across 20,933 wallets after a Sept. 30 private-key exposure.
- Bitquery linked the drain wallet to 27 earlier TradeWiz trades, raising questions about key security.
- Tradewiz faces pressure to complete refunds and explain how SOL PVP wallet keys were exposed.
Bitquery Traces $459K Tradewiz Drain to Wallet Used in 27 Trades
Before collecting stolen crypto, the wallet had helped pay for ordinary memecoin trades.
That is the unexpected finding in Bitquery’s investigation of Tradewiz, the Solana trading bot whose users suffered a September 30 wallet drain.
Researchers linked the address collecting stolen funds to another wallet that made 27 trades through Tradewiz a month earlier. Their accounting identified 20,933 affected wallets and approximately $459,000 taken in SOL, tokens, and deposits recovered by closing token accounts. The estimate values SOL at $120.
The connection offers investigators a starting point. It does not establish who controlled the wallets or how the private keys were exposed.
The Bot Stopped but the Theft Continued
Bitquery found that trading activity through the bot stopped 41 minutes into the main drain. About 73% of the SOL swept in that operation was taken afterward.
Tradewiz’s September 30 security notice on X attributed the incident to private-key exposure involving its SOL PVP export feature. It instructed customers to stop using existing SOL PVP wallet addresses.
“We will fully compensate users for losses caused by this incident,” the company wrote.
A later X update said the first refunds had been sent and that each claim required verification. Tradewiz also announced a precautionary pause in EVM services while it conducted security checks.
Those statements leave customers with two separate questions: when their losses will be reimbursed, and what failed in the system protecting their wallets.
A Security Promise Meets a Private-Key Leak
Tradewiz’s own documentation makes the incident particularly uncomfortable.
Its FAQ allows users to import and export wallet keys, but recommends against exporting them. It states: “By not exporting your private keys, we can ensure 100% security of your assets.”
The company’s subsequent disclosure puts that assurance under scrutiny. Users need an explanation of which wallets were exposed, how the export feature was compromised, and what changed before services resumed.
The public statements issued so far by Tradewiz describe security upgrades and compensation commitments without resolving those questions.
The Trail Reaches Exchange Accounts
On October 1, Tradewiz said on X that police were assisting with asset tracing and had contacted exchanges to seek identity and account-verification information.
The company also offered to consider foregoing further legal action, where legally permitted, if those responsible cooperated and returned the assets.

Bitquery traced earlier funding to MEXC withdrawals and later transfers toward a Kucoin deposit address. Those connections do not implicate either exchange in the theft. However, they identify potential records for investigators to pursue.
For affected traders, the next meaningful evidence will be completed reimbursements and a technical account of the breach. For investigators, the earlier customer activity may prove more useful than the theft itself.


