Examples
Each example takes one public incident from the repository’s
cases/incidents/
directory and answers one question about it. The steps are the tool calls in
the order an investigator would make them, with their arguments and a trimmed
excerpt of each answer. The case file for each incident holds the addresses,
the digests and the published sources the steps rely on.
| Example | Question it answers |
|---|---|
| Cetus CLMM exploit | What did an exploit wallet take, from which pools, and where did it send the proceeds off Sui? |
| KONG SUI rug pull | Could the deployer still mint or upgrade, who sold into the pool, and where did the sale proceeds go? |
| claim::swapS drainer kit | How did a drainer package take staked SUI while a dry run showed no loss, and who collected it? |
| WAL claim farm | Do the wallets that claimed and swept an airdrop to one address share a funder, and does a control group? |
| Typus oracle authority check | Which package version was live at an exploit, who could call the price update, and what did the fix change? |
Reading the excerpts
Section titled “Reading the excerpts”- An excerpt keeps only the fields that answer the step’s question.
…marks what was cut. Full answers carry more fields, and USD values, which come from a price provider, are left out. - Tool names link to the tool reference. Several of these
tools are outside the default
coreprofile; see Tool profiles to load them. - Anomaly flags, clusters and deposit-address verdicts are leads. A check that did not match clears nothing.