
Crypto's infamous exit scam, 18 months later
On February 14, 2025, Argentina's President tweeted support for a Solana token called $LIBRA. Within 45 minutes, it reached a peak market value of nearly $4.6 billion, then plummeted 94% over the next 11 hours. Wallets linked to the launch team withdrew about $107 million from its liquidity pools. Eighteen months later, there are still no criminal charges: four days ago, an Argentine court removed the last private complainants from the only remaining case, the funds a US court once froze have been released and spent, and wallets from the same cluster are trading memecoins again.

$LIBRA may be the best-documented crypto rug pull on record. This report presents the complete technical record, using only verifiable sources such as block explorers, court records, and published forensic research. Chainlabs has independently checked all main figures against the Solana mainnet. Every wallet mentioned here links to a full, checkable address.
Built to extract
The token with mint address Bo9jh3wsmcC2AjakLWzNmKJ3SgtZmXEcSaW7L2FAvUsU (the same 44 characters shown in the presidential tweet) was created on Solana at 21:38* on February 14, less than 30 minutes before Milei's tweet at 22:01.[1][2] Signer-level verification shows the deployer armed the Meteora liquidity pools about ten minutes before the tweet.[2][3] The pools were single-sided, holding only $LIBRA and no real asset.[3][2] We checked the token's setup directly: about 1 billion tokens, mint and freeze authority revoked. At the time, that may have looked like a trust signal. In hindsight, it was cosmetic — the extraction ran through the pools, not the mint.
During the first hour, Bubblemaps identified three red flags: 82% of supply held in a single wallet cluster with no public distribution plan; single-sided liquidity with no real asset paired; and more than $25 million in pool fees generated in just 60 minutes — a volume retail trading doesn't produce, consistent with minting against buy pressure or direct extraction.[3]
A June 2026 forensic report by Argentina's Federal Police (PFA Cybercrime Division), ordered by prosecutor Eduardo Taiano, added a key detail. The contract had no public record before the presidential tweet; it was not listed, indexed, or circulating. The first consumer app to offer the token did so about two and a half hours after the tweet. Before that, only people who contacted the creators directly could obtain the contract address.[2]
The snipers: first on the scene
Fernando Molina is a researcher whose work informed Argentina's congressional inquiry. He found 87 transactions from 74 wallets that bought $13.5 million of LIBRA in the seconds around the tweet, before any real price discovery. Of those 74, 62 turned a profit — the top three earning $8.5 million, $6.5 million, and $5.5 million on their full positions.[4] The PFA report confirms these 74 wallets bought "seconds before" the post and remain unidentified.[2] Molina also found a test token minted minutes earlier called "$MILEI." Around 63 of its ~70 wallets later traded LIBRA on launch day. This was a timestamped rehearsal.[5]
The winners took about $180 million; the losers realised $251 million in losses across 114,410 wallets.[1][6]
How the money left
The team didn't dump on the open market. Instead, they added one-sided pools holding only $LIBRA and withdrew USDC and SOL from the existing pools. This allowed them to swap into real assets without triggering a sharp price collapse, only a gradual bleed. In the first hour of the exit, starting around Feb 15, 00:30, roughly $87 million left the pools across five destinations: four collection wallets plus a Squads multisig vault (amounts and addresses in the annex). One transfer stands out.
The largest destination was a Squads multisig vault labelled on-chain "Milei CATA."[3] It required multiple keyholders to approve any movement. That label was self-assigned by the vault's controllers; it does not prove any connection to the President, only that someone chose to use his name. Labels show only what their creators enter, so provenance matters even more. We refer to it as the CATA Vault throughout. Verifying this tranche on Solana mainnet, we discovered a detail missing from earlier reports: at 00:33, the vault's receiving account got a $1 test transfer; six minutes later, between 00:39 and 00:44, four inflows brought its balance to exactly $42,794,677.81. The test came first, then the real money. During this verification, we resolved the vault's full address, which had previously been reported only as a prefix.
Lookonchain's parallel count: 8 team wallets totalling $107 million (57.6M USDC and 249,671 SOL), all linked to the deployer, the Creator Wallet.[7]
One address collapses the cluster
A key attribution break came days later: Bubblemaps identified an Ethereum address — the Master Key (0xcEA…) — as the common funding source behind both the $LIBRA and $MELANIA deployers. This was shown through cross-chain transfers, shared exchange deposit accounts, and matching funding patterns.[3][8] Court filings, combined with Hayden Davis's public admission to Coffeezilla that his team sniped both LIBRA and MELANIA, linked the cluster to Davis and Kelsier Ventures.[9][10] The same operator structure sat behind at least five other launches, all tracing back to the Master Key.[3][11]
Where the money went

May 27–28, 2025: At Burwick Law's request, Judge Jennifer Rochon's court (SDNY, Hurlock v. Kelsier, 1:25-cv-03891) issued a temporary restraining order; Circle froze $57.65M USDC across two accounts: $44.59M in the CATA Vault, and $13.06M in an account we verified belongs to the Creator Wallet.[12][13] We confirmed the freezeAccount instruction on-chain (May 28, 03:18) and the ownership chain behind it.
August 19, 2025: Rochon dissolved the TRO — no irreparable harm shown, defendants not evasive.[14] The funds have remained unfrozen since.[15] The on-chain thawAccount was executed September 4, 2025.
November 18, 2025: A cluster wallet and the CATA Vault woke after nine months and rotated $60M USDC → SOL.[3] The vault's balance went from 44,593,888 USDC to 0.56 between 04:38 and 05:57 - eighty minutes of roughly $500,000 to $2 million chunks.
February 2026: Six active wallets in the cluster were buying trending Solana memecoins ($PUMP, $TROVE, $PENGUIN), down about $3M on the activity.[3]
Since then, the Creator Wallet hasn't signed a single transaction. It has continued to receive unsolicited inflows; about 150 since March 2026. Most are dusting bots pinging the address every two hours; one, on June 30, was a spam token airdrop of 650 million units. None of this is operator activity; it's just noise around a known address. Verifying at the signer level is what separates reporting what a wallet moved from reporting what actually happened.
As of July 2026, the SDNY class action remains active but stalled: motions to dismiss have sat fully briefed since November 2025, and discovery is stayed.[15] In Argentina, 18 months on, there have been no indictments or depositions. On July 3, 2026, the court removed all private complainants from the case.[16] The requested Interpol red notice for Davis was never issued.[17]
The ledger and its limits
The uncomfortable truth isn't a failure of on-chain forensics; in fact, the forensics worked perfectly. Yet it changed nothing. The true limitation in crypto enforcement is what institutions choose to do with the evidence.
The blockchain proved premeditation, coordination, operator identity, and the exact path of every dollar that left the pools. What it could not show is the political angle: who in the Argentine government knew what, or whether anything valuable changed hands. Prosecutors' phone forensics revealed calls between the President and the intermediary Mauricio Novelli around the launch, as well as draft documents mentioning a $5 million arrangement. These are allegations denied by the government and unconfirmed by any court.[18][19] The PFA's finding that only the creators could have supplied the contract address is the closest the record comes to connecting on-chain and off-chain evidence — a finding made possible by the underlying data being public, unchangeable, and auditable.[2][3][15]
Implications for crypto screening
Every sign that $LIBRA was an extraction was visible in the first hour using public tools: concentrated supply, no tokenomics, abnormal fee generation, and sniper timing. Tracing the people behind it (deployer history, funding sources, cross-chain links, shared exchange deposit accounts) requires repeatable methods rather than luck.
The Kelsier cluster is set apart from the norm by clear attribution: labels traceable to the exact transaction that supports them. Attribution should be traceable to the underlying evidence. That's the standard Chainlabs applies to every label, and it's why the gap in this story is so visible. No one can call the evidence into question when it's been checked down to the last cent. But, as $LIBRA shows, money moves long before the courts do.
All timestamps are UTC. Every re-verified address can be checked on its native chain's public explorers. Allegations are identified as such; no individual named has been criminally convicted in connection with $LIBRA as of July 8, 2026.
Citations
[1] Nansen — LIBRA: The Aftermath — research.nansen.ai/articles/libra-the-aftermath
[2] Infobae — Argentine Federal Police forensic report — infobae.com
[3] Bubblemaps — The LIBRA Playbook — blog.bubblemaps.io
[4] elDiarioAR — eldiarioar.com
[5] La Política Online — lapoliticaonline.com
[6] La Nación — Congressional commission report — lanacion.com.ar
[7] Lookonchain — x.com/lookonchain/status/1890619615883219455
[8] The Block — LIBRA/MELANIA link — theblock.co
[9] The Block — Hayden Davis admission — theblock.co
[10] CoinDesk — MELANIA admission — coindesk.com
[11] The Block — WOLF connection — theblock.co
[12] Decrypt — Circle freeze — decrypt.co
[13] Arkham Intelligence — twitter.com/arkham/status/1927801316178546958
[14] Decrypt — TRO dissolved — decrypt.co
[15] CourtListener docket — courtlistener.com
[16] La Nación — complainants removed — lanacion.com.ar
[17] Protos — protos.com
[18] Chequeado — chequeado.com
[19] CoinDesk — Milei call logs — coindesk.com