CeFi suspicious withdrawals vs DeFi oracle manipulation
Compare how ChainVector Analyst investigates exchange-side account takeover and protocol-side exploit paths using the same evidence-driven SOC workflow.
BX-104 Suspicious Withdrawal
ChainVector investigates a suspicious 420 ETH withdrawal using login telemetry, API activity, withdrawal velocity, wallet risk, and replay analysis.
Key Signals
- Unfamiliar login geography
- Dormant API key activation
- 420 ETH withdrawal request
- Mixer-proximate destination wallet
Outputs
- Analyst timeline
- Evidence drawer
- SOC report export
- Attack replay
CV-2041 Flash Loan Oracle Manipulation
ChainVector investigates a flash-loan-assisted oracle manipulation using pool state, swap sequence, oracle deviation, borrow extraction, wallet clustering, and mitigation replay.
Key Signals
- 80,000,000 USDC flash loan
- CITY / USDC pool imbalance
- +32.4% oracle move
- 12,000 ETH estimated impact
Outputs
- DeFi analyst timeline
- Evidence drawer
- SOC report export
- Mitigation replay
Capability comparison
| Category | BX-104 | CV-2041 |
|---|---|---|
| Domain | CeFi / Exchange | DeFi / Protocol |
| Primary threat | Account takeover with suspicious withdrawal | Flash-loan-assisted oracle manipulation |
| Entity under protection | User account, exchange withdrawal flow | Protocol liquidity, oracle integrity, lending market |
| Core telemetry | Login history, API activity, withdrawal velocity, wallet risk | Pool state, swap sequence, oracle history, borrow positions, wallet cluster |
| MCP tool pattern | get_alert, get_withdrawal, get_user_login_history, get_api_key_activity | get_pool_state, get_swap_sequence, get_oracle_history, get_borrow_positions |
| Evidence artifacts | Login anomaly, API anomaly, wallet risk | Pool imbalance, oracle deviation, borrow extraction, profit dispersion |
| Replay type | Attack replay and response recommendation | Mitigation replay across circuit breaker, TWAP, collateral caps |
| SOC output | JSON / PDF / Copy report | JSON / PDF / Copy report |
| Ideal buyer | Exchanges, custodians, CeFi security teams | Protocol teams, DeFi security teams, risk teams |
Domain
- BX-104
- CeFi / Exchange
- CV-2041
- DeFi / Protocol
Primary threat
- BX-104
- Account takeover with suspicious withdrawal
- CV-2041
- Flash-loan-assisted oracle manipulation
Entity under protection
- BX-104
- User account, exchange withdrawal flow
- CV-2041
- Protocol liquidity, oracle integrity, lending market
Core telemetry
- BX-104
- Login history, API activity, withdrawal velocity, wallet risk
- CV-2041
- Pool state, swap sequence, oracle history, borrow positions, wallet cluster
MCP tool pattern
- BX-104
- get_alert, get_withdrawal, get_user_login_history, get_api_key_activity
- CV-2041
- get_pool_state, get_swap_sequence, get_oracle_history, get_borrow_positions
Evidence artifacts
- BX-104
- Login anomaly, API anomaly, wallet risk
- CV-2041
- Pool imbalance, oracle deviation, borrow extraction, profit dispersion
Replay type
- BX-104
- Attack replay and response recommendation
- CV-2041
- Mitigation replay across circuit breaker, TWAP, collateral caps
SOC output
- BX-104
- JSON / PDF / Copy report
- CV-2041
- JSON / PDF / Copy report
Ideal buyer
- BX-104
- Exchanges, custodians, CeFi security teams
- CV-2041
- Protocol teams, DeFi security teams, risk teams
Different attack domains, same ChainVector workflow
Detect
BX-104 detects a suspicious withdrawal alert; CV-2041 detects a flash-loan capital injection.
Investigate
Both run a simulated MCP tool-call transcript scoped to their domain — exchange telemetry or on-chain telemetry.
Correlate evidence
Independent signals (login/API/wallet or pool/oracle/borrow) are linked into one coherent finding.
Generate SOC report
Both produce the same JSON / PDF / Copy Report export shape, just populated from different telemetry.
Replay response path
BX-104 replays the attack timeline; CV-2041 replays candidate protocol mitigations.
Why this matters
One analyst workflow
Teams can investigate CeFi and DeFi incidents without switching between disconnected tools.
Evidence-first AI
ChainVector conclusions are tied to tool outputs, telemetry, and replayable evidence.
Security plus go-to-market clarity
Each demo doubles as a sales asset, showing buyers exactly how ChainVector would support their environment.
Which ChainVector investigation fits your environment?
Exchange / CeFi team
Walk through BX-104 and see how ChainVector handles suspicious withdrawals, account takeover, and wallet-risk response.
Request BX-104 WalkthroughProtocol / DeFi team
Walk through CV-2041 and see how ChainVector handles oracle manipulation, exploit-path reconstruction, and mitigation replay.
Request CV-2041 WalkthroughNeed custom monitoring?
Talk to Solid Source Systems about ChainVector deployment, MCP connectors, custom detection engineering, and incident workflows.
Talk to Solid Source Systems