URGENT SECURITY INCIDENT & COMPLIANCE ESCALATION: Request for RAILGUN Core Team to Initiate Circle Blacklist/Freeze
To the RAILGUN Core Developers, Railway Support, and Security Committee,
I am formally submitting an urgent report regarding a protocol-level routing vulnerability that resulted in the loss of 49,922.697753 USDC from RAILGUN public infrastructure.
The stolen funds CURRENTLY REMAIN INTACT on Ethereum Mainnet in the exploiter's EOA (0x92362d46B3D2DC11fb90a7468c9133aa88A371AD). We have a critical, time-sensitive window to request an emergency smart contract blacklist from Circle.
ON-CHAIN EVIDENCE & ROUTING FAILURE SUMMARY:
Public Relayer Address Misdirection:
Misrouted Target: 0xFc2D3c4e8d186371FAc8A078d64338aF014a0749 (RAILGUN Public Relayer / Broadcaster)
Unshield Refund Tx Hash: 0x7f7b9b625adbdc076e314981acc58ddcdfffb7f77a84e4ca821210adcf9387ac
Description: When executing a fallback unshield, the SDK's routing logic failed to resolve the depositor's origin EOA and erroneously credited 49,922.697753 USDC into RAILGUN's public relayer node.
Public Infrastructure Drain:
Exploiter Address: 0x92362d46B3D2DC11fb90a7468c9133aa88A371AD
Exploitative Drain Tx Hash: 0x9868723a4f0a08cffb44372d7921b9c836f45049ace163f3f0bcd5a08dd0bca0
Description: An external sweeper bot/entity injected gas into the public relayer address and drained the full 49,922.697753 USDC to 0x92362d46B3D2DC11fb90a7468c9133aa88A371AD.
REASON FOR PROTOCOL-LEVEL INTERVENTION:
The affected address (0xFc2D...0749) is part of RAILGUN's public relay network infrastructure, not a private user EOA. Because user funds were exposed due to a protocol fallback anomaly and swept from public infrastructure, RAILGUN core security operators have the official standing and logs required to coordinate with Circle Compliance.
ACTION REQUIRED FROM CORE TEAM:
Immediately contact Circle Compliance & Law Enforcement Liaison on behalf of the RAILGUN protocol/DAO to request an emergency smart contract blacklist/freeze on 0x92362d46B3D2DC11fb90a7468c9133aa88A371AD.
Escalate this edge-case unshield fallback routing bug to core engineers to prevent further misdirection of unshielded assets to public relayers.
Please confirm as soon as the official outreach to Circle has been submitted.
URGENT SECURITY INCIDENT & COMPLIANCE ESCALATION: Request for RAILGUN Core Team to Initiate Circle Blacklist/Freeze
To the RAILGUN Core Developers, Railway Support, and Security Committee,
I am formally submitting an urgent report regarding a protocol-level routing vulnerability that resulted in the loss of 49,922.697753 USDC from RAILGUN public infrastructure.
The stolen funds CURRENTLY REMAIN INTACT on Ethereum Mainnet in the exploiter's EOA (0x92362d46B3D2DC11fb90a7468c9133aa88A371AD). We have a critical, time-sensitive window to request an emergency smart contract blacklist from Circle.
ON-CHAIN EVIDENCE & ROUTING FAILURE SUMMARY:
Public Relayer Address Misdirection:
Misrouted Target: 0xFc2D3c4e8d186371FAc8A078d64338aF014a0749 (RAILGUN Public Relayer / Broadcaster)
Unshield Refund Tx Hash: 0x7f7b9b625adbdc076e314981acc58ddcdfffb7f77a84e4ca821210adcf9387ac
Description: When executing a fallback unshield, the SDK's routing logic failed to resolve the depositor's origin EOA and erroneously credited 49,922.697753 USDC into RAILGUN's public relayer node.
Public Infrastructure Drain:
Exploiter Address: 0x92362d46B3D2DC11fb90a7468c9133aa88A371AD
Exploitative Drain Tx Hash: 0x9868723a4f0a08cffb44372d7921b9c836f45049ace163f3f0bcd5a08dd0bca0
Description: An external sweeper bot/entity injected gas into the public relayer address and drained the full 49,922.697753 USDC to 0x92362d46B3D2DC11fb90a7468c9133aa88A371AD.
REASON FOR PROTOCOL-LEVEL INTERVENTION:
The affected address (0xFc2D...0749) is part of RAILGUN's public relay network infrastructure, not a private user EOA. Because user funds were exposed due to a protocol fallback anomaly and swept from public infrastructure, RAILGUN core security operators have the official standing and logs required to coordinate with Circle Compliance.
ACTION REQUIRED FROM CORE TEAM:
Immediately contact Circle Compliance & Law Enforcement Liaison on behalf of the RAILGUN protocol/DAO to request an emergency smart contract blacklist/freeze on 0x92362d46B3D2DC11fb90a7468c9133aa88A371AD.
Escalate this edge-case unshield fallback routing bug to core engineers to prevent further misdirection of unshielded assets to public relayers.
Please confirm as soon as the official outreach to Circle has been submitted.