wurrly

InfrastructureInferred

BitGo wallet infrastructure

5 registry addresses

Observed portfolio value

Reading balances

No successful balance read yet.

The 5,132-byte multisig template (method Send Multi Sig) shared by AVAT's filed wallets, AVX's vaults and a 2022 wallet; forwarders that sweep into it. Same template, different customers.

Holdings

AVAX and the listed tokens, across the addresses in scopeThe price read has not finished. The quantities below are measured; USD values follow.24 h value change unavailable. No read returns a second valued endpoint 24 hours earlier.

Reading balances

Requested: Registered AVAX and liquid-staking balances. Returned coverage unavailable. Chains requested: C. 5 eligible addresses; none read yet.

Source: Avalanche C-Chain RPC, Wurrly Intel registry. No successful read yet.

Read method

Every figure is summed in exact decimal over one asset key at a time. A chain figure adds the priced holdings measured on that chain; an asset the price read could not answer for is left out of the sum, and the cell says how many were left out. A share is that chain figure over the summed priced holdings in the selected scope, divided at 60 decimal places and shown at two.

The P-Chain balance is one measurement for the whole owner group, so an address row on that chain shows the group note instead of a figure of its own. C-Chain AVAX and P-Chain AVAX are separate asset keys and are never added into one line.

No route this card reads returns a valued endpoint twenty-four hours back over the same addresses and assets, so the 24 h change is unavailable in every row. The price route’s own daily move is the AVAX market, which is a different measurement.

Balance history

History range
Display unit
Requested dates follow the read's own successful timestamp.Daily balance, rebuilt from returned transactions and anchored to the live balance

Reading balance history

Requested: C-Chain AVAX only, daily. Returned coverage unavailable. Chains requested: C. 5 eligible addresses; none read yet.

Source: Routescan, Wurrly Intel registry. No successful read yet.

Transaction count unavailable. Anchor time unavailable.

Current positions. Read time unavailable. Staking positions unavailable for this read.

Reading current staking positions

Read method

The series is rebuilt from the transactions the feeds return and then shifted so its last figure equals the live balance the node reported. The shift is the anchor adjustment, and the reach of the feeds behind it is stated above. Nothing is drawn before that shift is proved.

A day's figure is that UTC day's close: the balance after every movement dated that day.

Historical USD is each slot day's own final recorded close for AVAX, from Coinbase Exchange, joined on the UTC day. A day that has not finished has no close, and no other day's price stands in for it. The C-Chain and P-Chain AVAX are the same asset in that market, so both join the one AVAX close. Price join revision 2026-09-14.

Quantity coverage start unavailable.

Flows

Transfers summed by counterparty over the selected window
Flow window

Reading transfer history

Requested: External AVAX transfers of at least 1 AVAX, summed by counterparty. Returned coverage unavailable. Minimum transfer: 1 AVAX. Chains requested: C. 5 eligible addresses; none read yet.

Source: Routescan, Wurrly Intel registry. No successful read yet.

Read method

A trailing window is the interval from the read’s own time minus 30 periods of 24 hours up to that time. The start instant is excluded and the end instant is included, so two adjacent windows never both count the moment they share. Every figure in a trailing window is summed from the dated transfer rows the read returned, one row at a time, in exact decimal.

The returned history is the source’s own aggregate, summed over every row it read rather than over the rows it sent. It is never filtered by its first and last date to make a trailing total: a window that the returned rows cannot reach is reported as unavailable instead.

Inflow is AVAX this subject received and outflow is AVAX it sent. A movement with this subject on both sides is internal and is counted but never summed into an external total; a row with this subject on neither side is unmatched and is counted the same way. A row the feeds dated unreadably belongs to no trailing window, and the count of those is stated above.

Every amount on this card arrived from the source as a JavaScript number, so the sums are exact over the figures received and the received figures are not exact to the last digit of the chain. Each row’s Details says so beside the figure it applies to.

Transfers

Returned transfers, newest firstMinimum transfer: 1 AVAX

Reading transfer history

Requested: Returned AVAX transfers of at least 1 AVAX, newest first, including movements between the subject's own addresses. Returned coverage unavailable. Minimum transfer: 1 AVAX. Chains requested: C. 5 eligible addresses; none read yet.

Source: Routescan, Wurrly Intel registry. No successful read yet.

Read method

These are the transfers the flow read returned, newest first. The same request answers the card above: one read of the source, two measurements of it. Every row is at least 1 AVAX, because the source drops everything below that before it answers, and there are no token rows in it, so no token quantity is ever compared against the numeric 1 of another asset’s unit. A different threshold would need a source that reads to a different depth, which is not a setting on this page.

TRANSFERS shows every returned row, including movements between this subject’s own addresses, each marked Internal. A subject’s own P-Chain key counts as its own in both spellings, so a wallet moving value between its C-Chain and P-Chain sides is Internal rather than a pair of external flows to itself. INFLOW and OUTFLOW are external directions relative to this subject and exclude those rows, and they exclude rows with this subject on neither side and rows whose other endpoint is a chain rather than an address, which have no direction to sort into. CROSS-CHAIN holds the movements between two Avalanche chains: two endpoint chains that differ, or the atomic feed, which returns nothing else.

No pair identifier reaches this page, so a cross-chain export and its matching import are two rows with two amounts and two links. Nothing on this card adds them into one movement, and no figure here counts a pair once.

A historical USD value is that row’s own UTC day’s final closing price multiplied by its exact quantity. A day that has not finished has no close and says so; a day the price read did not return says so separately. Today’s price is never substituted for either.

Pages are windows on the frozen read named in the footer. A newer read landing while you are reading does not replace these rows; it offers itself at the top of the card, and adopting it returns to page 1.

Visualizer

Registry addresses as boxes, and the transfers the read observed between themRegistry addresses are grouped by role. Arrows show transfers returned by the selected read.A counterparty is the address or organisation on the other side of a transfer.

BitGo wallet infrastructure. Reading transfers

Visualizer view

BitGo wallet infrastructure: registry addresses by role, and the transfers this read observed between them5 boxes and no arrows. Transfer coverage is being read.Custody2 addressestreasury, vaults, signersWorking3 addressesstaging, pass-throughs, forwardersBitGo-template wallet c…vault · C-Chain · Inferred0xd6df…843bBitGo signer of AVAT wa…signer · C-Chain · Proven0x1705…efe8BitGo forwarder (1,250 …forwarder · C-Chain · Proven0x24e8…a379BitGo forwarder (1,250 …forwarder · C-Chain · Proven0xece2…de47BitGo forwarder (1,250 …forwarder · C-Chain · Proven0xa1e6…f661

Select an address to read its identity and observed transfers.

Registry addresses in scope, with each one's role. 5 of 5 addresses read.

Wurrly Intel registry: compiled with this page.

Reading transfers. Transfer coverage is being read.

No transfer read has answered for this scope.

Read method

The boxes are the registry’s own rows, placed by the role the research gave each one: custody first, the working wallets next, the staking and protocol keys, then the exits. Whoever was on the other side of a returned transfer joins an outer column, on the right when this subject paid them and on the left when they only paid in. Grouping is not attribution: a box is named only where the registry names it.

Arrows are the transfers this read returned, summed by pair, asset, chain and kind. Two assets between one pair of boxes are two arrows, never one; a token quantity is never added to an AVAX total and never takes the AVAX reporting threshold. Reverse directions stay apart. A sum is labelled At least only where the source states the depth it reports to and says its coverage was partial; otherwise it is labelled Observed, which is still scoped to this request.

An endpoint the feed left as a chain rather than an address is not a counterparty, so no arrow is drawn to it and the count of transfers that were excluded for that reason is stated in the scope line above.

A column of more than 8 addresses folds its tail behind one control. Folding changes the drawing and nothing else: Connections still lists every canonical relationship, and any movement whose two ends fold into one box is kept as that group’s own internal subtotal, so the arrows plus the subtotals still add up to the same per-asset totals.

Proven: a filed quantity matched to the unit, or a transaction identified by its hash. Inferred: behaviour or timing, with the base rate stated in the source. Candidate: a lead, one tier below inferred, with a written test for promoting it and a written test for killing it. Explorer tag: an explorer's attribution label. Standing describes the cited claim. A transfer alone does not establish ownership.

Minimum transfer: 1 AVAX.

Evidence

Registry claims, address by address, with each claim's standing5 of 5 registry addresses on C-Chain; all registry evidence shown.

Proven: a filed quantity matched to the unit, or a transaction identified by its hash. Inferred: behaviour or timing, with the base rate stated in the source. Candidate: a lead, one tier below inferred, with a written test for promoting it and a written test for killing it. Explorer tag: an explorer's attribution label. Unattributed: no ownership attribution is established in the registry. Standing describes the cited claim. A transfer alone does not establish ownership.

Evidence class: A flow tie, B co-signature or shared infrastructure, C filed-quantity match, D node or provider continuity, E adjacency.

Registry method states a review on 4 September 2026. No record states a review date of its own.

  1. BitGo forwarder (1,250 B)

    ProvenC-Chainforwarder

    0x24e88d6be89fd2c40c577e8a8e3c284d9a10a379

    Attribution
    Filed under BitGo wallet infrastructure as forwarder. Open entity
    Claim supported
    sweeps AVX vault payouts (767K) into the 2022 BitGo wallet 0xd6df5e97
    Evidence
    internal txs
    Source
    Source destination unavailable

    Open addressOpen in Snowscan (opens in a new tab)

  2. BitGo forwarder (1,250 B)

    ProvenC-Chainforwarder

    0xece2c919be54e7828be6e90c2c11116ecc8dde47

    Attribution
    Filed under BitGo wallet infrastructure as forwarder. Open entity
    Claim supported
    sweeps AVX vault payouts (767K) into the 2022 BitGo wallet 0xd6df5e97
    Evidence
    internal txs
    Source
    Source destination unavailable

    Open addressOpen in Snowscan (opens in a new tab)

  3. BitGo forwarder (1,250 B)

    ProvenC-Chainforwarder

    0xa1e6cf3912287a67d222e215e6a69a62ddb6f661

    Attribution
    Filed under BitGo wallet infrastructure as forwarder. Open entity
    Claim supported
    sweeps AVX vault payouts (767K) into the 2022 BitGo wallet 0xd6df5e97
    Evidence
    internal txs
    Source
    Source destination unavailable

    Open addressOpen in Snowscan (opens in a new tab)

  4. BitGo-template wallet created 2022-03-29 by…

    InferredC-Chainvault

    0xd6df5e97232a5e8d1fc9edaac255ae618895843b

    Attribution
    Filed under BitGo wallet infrastructure as vault. Open entity
    Claim supported
    0x990ff058 (Arkham: deployer BitGo?) - exchanges funds with the AVX vault both ways: 686,880 into 0xd50b, 775,803 back via forwarders; owner unattributed, evidently the same enterprise
    Evidence
    390 payouts to 88 since 2022
    Source
    Source destination unavailable

    Open addressOpen in Snowscan (opens in a new tab)

  5. BitGo signer of AVAT wallets A and B

    ProvenC-Chainsigner

    0x1705500d222d24e9dc6754f6ce1d3b6802aeefe8

    Attribution
    Filed under BitGo wallet infrastructure as signer. Open entity
    Claim supported
    sent all 44 transactions those two wallets ever received and one more to the unused third wallet, 45 in its life, and has been silent since 19:39:28 UTC on 11 Jun 2026. The key is BitGo-side infrastructure provisioned for this customer: the unrelated template wallet 0x4a61abc3 gas-funded it 1.0 AVAX 103 minutes before its first deployment
    Evidence
    scratch/hunt/blue/CANDIDATES.md item 4 and bitgo-templates.md section 6: 44 of 44 transactions into wallets A and B came from this key, 2 of them sendMultiSigToken. Re-run: GET https://api.routescan.io/v2/network/mainnet/evm/43114/etherscan/api?module=account&action=txlist&address=0x1705500d222d24e9dc6754f6ce1d3b6802aeefe8&sort=desc&offset=100
    Source
    Source destination unavailable

    How this row was graded

    Evidence class
    A, flow tie

    Open addressOpen in Snowscan (opens in a new tab)

Registry claims, address by address, with each claim's standing. 5 of 5 addresses read.

Wurrly Intel registry: compiled with this page.

Source: research address registry. 5 registry addresses for this subject, every one of them shown.

Read method

Nothing here is a new claim. The registry is the research’s label sheet: an address enters it when a figure on one of the research pages established it, and it takes that figure’s standing. This card restates those rows; it does not add to them, and it never upgrades a standing.

Registry method states a review on 4 September 2026. That is the method’s assertion about the whole sheet rather than a date filed against any one row, so it is not copied into a record. A record the registry files no review date against says so.

A source link renders only where this application resolved the destination itself. The one destination the registry files per entity is the research article that entity is written up on, and it is labelled Related research rather than presented as the citation for an individual address’s figure. No anchor, filing URL or transaction hash is derived from evidence prose.

A candidate is a lead one tier below inferred, and it attributes nothing. Where the registry grades a row, the grade, the evidence class and the two tests are printed as the research wrote them, and a confidence appears only on a row that carries a number. A proven row prints no confidence and neither test: nobody measured a number for it, and a row already at the top standing has nothing written that would move it up or out. Promotion is a person's decision, and every promotion writes the re-runnable query into the evidence above.

An explorer link, where one is shown, is an inspection destination and not evidence of ownership. Snowscan reads the C-Chain and Avascan reads the P-Chain.