Two Storefronts, One Clearinghouse: Inside 马上支付's TRON Mule Network
Two collection wallets, advertised in two Telegram channels with no visible connection, converge within three hops of their main hubs on the same unlabeled clearing layer. One hub in it has moved $815 million. Neither of the two address-label directories we queried has a name for it. And one of the storefront's own websites, hssjjw669497.top, says in its own copy what it is for: laundering gambling and adult-site money, under the name of a 55,804-member escrow group.
A storefront that never closes
Most cash-to-crypto mule ads post a rate and a contact handle. The platform we started pulling on, broadcast on Telegram as 马上支付 (“Pay Now”), runs a full self-service order system instead: a live site at yh271.top, open 24 hours, page-titled 支付宝小额洗口令, with a tiered commission schedule printed like a menu.
The uplift narrows as the order grows, the shape of a volume price list. And yh271.top is not a one-off. The same cluster of Telegram bot handles, @zfb676767bot as the master bot plus @zfb7878, @zfb6767, @zfb6696 and @c7c7888top, recurs across seven confirmed domains on three hosting clusters. One operator, running the same storefront under enough names that losing a domain costs nothing.
Underneath sits a much larger piece of infrastructure: a Telegram escrow conglomerate called 土豆担保, 55,804 members deep, that underwrites these transactions the way a payment processor underwrites a merchant. Its customer-service account, @tppdbb, surfaced independently on both sides of this investigation. The same conglomerate's channels sell DPI interception, SMS lookup and 杀猪盘 (pig-butchering) victim data on the side. The mule platform is a storefront on a criminal-services marketplace.
The footprint we hadn't mapped
Domain clustering only finds the mirrors you already know to look for. So we went back to the hosting layer and ran reverse lookups on the two IPs behind Clusters A and C. Both resolve to the same allocator: AS139659, LucidaCloud Limited, reselling NTT America capacity assigned to Nebula Global Limited of Kwun Tong, Hong Kong. Cluster B, a Uscloud VPS in Los Angeles on AS967, checks out as a distinct host. Its abuse contact, abuse@us-cloud.top, even shares the throwaway .top pattern of the mule domains.
The lookup on 207.57.131.47 surfaced eight domains the original mapping never caught. hssjjw669497.top turned out to be the most explicit page in the whole network; we come back to it below. hhhy271.top returns the identical page title to the confirmed storefront: a live mirror, and a better abuse-report target than the domain the operator calls permanent. kkxhht.top returns something else entirely, 线上大量招资金盘码接回车队, recruiting for a Ponzi-scheme payment-code operation. That is a second criminal product line on the same server, the pattern 土豆担保 already showed us: one piece of infrastructure, several lines of business.
The website that says it out loud
Most of these storefronts dress the service up as “red packet codes”. hssjjw669497.top, one of the eight domains the reverse lookup surfaced, does not bother. It sits on the same server as yh271.top, runs the same 24-hour self-service order flow, and headlines itself as the official small-amount Alipay wash of 土豆担保, the escrow group we had so far only connected to the platform through its customer-service account.
That is the clearest statement of purpose anywhere in this investigation, and it comes from the operator. The mule's ¥100 in is not a commission scheme in the abstract: it is the float that moves a gambling or adult-site customer's money through an account that is not the operator's. The page claims three years of stable operation and warns customers off “imitation” sites, the same trust pitch an escrow brand sells.
Its price list differs from yh271.top's, which suggests each storefront is priced on its own: ¥100 returns ¥190 here against ¥160 there, ¥1,000 returns ¥1,268 against ¥1,238, and ¥3,000 returns ¥3,357 against ¥3,487. A live ticker of masked QQ-mail “buyers” and sales counts in the hundreds of thousands per tier decorate the page. We treat both as marketing, not data.
Two channels, one trail
We picked up two threads in two Telegram channels that, on the surface, have nothing to do with each other.
The first, @cxdf99974, called itself 晨曦代发 and ran what looked like a China-to-India USDT brokerage. It posted a wallet, TR5vrSEQGuykJMEu4Xg8FxiRwWESb8m9t4, then archived most of its history and deleted itself.
The second, @yyyyiiiqq, an 8,431-member channel, simply posted a collection wallet in the open, TUnSzEACA4um4ac1b4eF2UZ79S9Kj9Agio, and let members send to it directly: 581 senders and 829 inbound transfers by the time we looked.
We traced both hop by hop on TRON, expecting two separate laundering circuits. They are not. Within three hops of each chain's main hub, both land in the same unidentified clearing layer. First, the parts of each chain we could put a name to.
Where the Huione money went
Ten hops out from the @cxdf99974 wallet sits an exit address, TLLQuFaTtqkR5GYrN5Ct2gwxsaNiJCy1pr, that has moved $40.5 million across 360 transfers from 1,073 senders. One hop further is a hub, TQdNsGQVbsyrFABfVFCCZomrs33YX9hGaK, that has absorbed $34.9 million from 5,794 distinct senders, then fans out into at least eight branches.
We traced one all the way through, branch A in Fig 3. It ends at THDCNSBw5m6t6tKQL473FenSKeXoggBRPA, which MetaSleuth's address-label API tags as a Huione Group deposit address. $1.12 million in USDT reached it across 167 transfers.
FinCEN found Huione Group to be of primary money laundering concern under Section 311 of the USA PATRIOT Act, proposed in May 2025 and finalised that October, cutting it off from US correspondent banking. In a nine-day window between those two dates, the address received five transfers of roughly $7,800 to $7,900 each, on 19, 20, 25, 26 and 28 August 2025, each verifiable on Tronscan by hash. One, for reference: 67450310907788dc457fca8d02cd6d8edd80bcca6dcb7b0d96c1ef7532eafac0, $7,838, 19 August at 13:36:51 UTC.
The exchanges on the other end
A parallel branch off the same hub tells a cleaner story. $2.65 million, in a single-receiver funnel, reaches TYYb45TeNHRJfS3qzUZ9wv3w29b6MvAWhd, a confirmed Binance deposit address, which in turn sweeps into TDqSquXBgUCLYvYC4XZgrprLK589dkhSCf, a Binance hot wallet confirmed by seven independent sources including Binance's own proof-of-reserves data.
Going back through the untraced branches found more. TK1roMJVFGNVKwxqce2hQX3QXGmpAvn2yU feeds two OKX deposit addresses, $84,000 across 12 transfers and $76,517 across 14, both confirmed by two separate commercial label services. A third address downstream of the same wallet resolves to a KuCoin deposit.
None of this shows Binance, OKX or KuCoin did anything wrong. A deposit address tells you which exchange controls the receiving account, not who opened it or what KYC is on file. It does mean that funds from a mule platform's wallet moved through all three exchanges' own deposit infrastructure.
Chain 2's own flagged wallet
The @yyyyiiiqq wallet tells a messier story. Its first stop, TUi9U3hbr6F81dmAvyNh4wpsg3TgeEwZdF, is a confirmed OKpay deposit address. OKpay is an unregulated Telegram guarantee and escrow market, not a licensed exchange. Two more wallets downstream, TKEMiZStBLnCq5ru1a3r7WTKVzfaSu3Mak and TYCBsKvJSrLoj6pudJCLFNFYdBcntNP1gU, are confirmed OKpay hot wallets, and the only two wallets in this investigation still holding material USDT: $2.47 million and $518,915 at our balance check. Everything else we traced, every Binance, Huione and OKX address included, has been swept to zero.
One hop on, a hub with 3,098 senders, TWRjHDpX17s3UXrZMhoDvC57imLDaq6uNn, feeds an address MetaSleuth tags, verbatim, “TG: Money Laundering”: TKvRidTgR8161NRSpYcTEfoREkiV9u777N, $564,900 across 250 transfers. But the hub's full outflow puts that flag in the minority. Its dominant outflow goes to three more confirmed Binance deposit addresses, over $800,000 in total. The flag was real. It just wasn't where most of the money went.
Two storefronts, one back end
This is the part that changed how we read the case. The “TG: Money Laundering” wallet from Chain 2 sends $4.89 million into TJN2ECgHG2bXNindDu6J3C4EPwCRce13q8. Completely independently, branch D off Chain 1's hub, TWuXEHo3uoixoNaX5eVfRHkQYKo3UoJXjC, sends $5.49 million into TNR7viapxa9F4fmK9tPuoPcKaom4kJ7NWV.
One more hop and both land in the same neighbourhood. TJN2ECgH and a second wallet, TYJ4qx7WKopJYz35sAfa7zXSkm6gA4jsYb, trade back and forth, $6.24 million one way and $7.34 million the other, and both feed the same downstream addresses. Unrelated wallets do not look like that. Sister sweep wallets on one shared back end do.
The scale of that back end is an order of magnitude beyond anything else in this investigation. TJN2ECgH has moved $44 million lifetime; TYJ4qx7W, $78.4 million. A hub downstream of both, TGN4R5AA1Ay1vM67x9AFVKjNcKWaLUU2dg, $53.2 million. Two more, TMWGR161XqRaHec8v3hyS1vPpucTDxeMWS and TD1zsUB3dZMU78VZcgr2WrYbGRDbb54Z6C, have moved $447 million and $815 million lifetime, the latter across more than 400,000 outbound transfers to 13,514 distinct receivers. TD1zsUB3 has shown no activity for over a year; the volume is historical.
None of it is labeled, not in Bitquery's address-label directory and not in MetaSleuth/BlockSec. We also ran a sponsor check, looking for a shared first funder across the five biggest hubs, the signature of a single sybil operator. No common funder. This is either a very large unregistered OTC operation or an exchange's internal infrastructure that neither directory has mapped, and two separate mule storefronts are both plugged into it.
What we're confident about, and what we're not
Everything here comes from public sources: TRON's ledger, pulled through Bitquery's on-chain API; entity attribution cross-checked against MetaSleuth/BlockSec's address-label API; and open Telegram channel monitoring. No exchange-held KYC, bank records or device data went into this piece.
“Confirmed” here means independently labeled by at least one of two named commercial label services. That is investigative intelligence, not legal certainty. All dollar figures are historical transfer totals, not live balances, except where we say otherwise.
On the surface this case is two small operations: one deleted brokerage channel and one open collection wallet. Underneath, both are customers of the same settlement system, and it is the largest thing in the picture by a wide margin.
We're continuing to watch the cluster, especially TD1zsUB3 and TMWGR161. If either resolves to a name, or the Huione-linked flow is acted on by Tether or law enforcement, we'll publish an update.
Two storefronts. One clearinghouse. No name on the door.