Back

Liquidity-removal incident anatomy

P13-L03 · P13 · P13-M01

Differentiate documented withdrawal from unsupported fraud attribution

HISTORICAL · needs_review

Prerequisites: P13-L02

Learning objectives

  • Differentiate documented withdrawal from unsupported fraud attribution
  • Reconcile a real historical pool Burn with token outflows and refuse unsupported intent attribution.

Why this matters

A real liquidity removal can occur in a migration or an ordinary redemption. The event itself and a fraud hypothesis need different evidence.

Explanation

HISTORICAL PROVENANCE WARNING: the frozen package is a bounded transcription of an Etherscan rendering inspected on 2 October 2026 for a 26 September 2020 event. The web tool may use a cached rendering. No byte-identical HTML, native receipt/header or block hash was independently captured. The historical record is not a current Radar assessment.

Inspect the exact transaction and pool in docs/academy-2/datasets/p13/withdrawal.json. The explorer renders a Burn event at displayed locator 15 with two integer amounts. Corresponding transfer locators 12/13 show the same amounts leaving the pool for the recorded destination. LP transfer/burn rows provide mechanism context. The outer call is decoded as migration; the package does not independently reconstruct destination custody or the entire migration trace.

Decode the two 32-byte Burn data words and compare them with the rendered raw transfer integers. The offline verifier checks these equalities and display conversions. That is reproducible indexed event analysis, not independent canonical inclusion. Exclude current USD panels and friendly entity labels: they are unnecessary to establish what the bounded record displays and can introduce time or identity confusion. A withdrawal observation supports a technical action; fraud, theft and intent remain separate unestablished claims.

Key terms

Burn event: protocol-specific liquidity-redemption event, distinct from a misconduct label.

Raw amount: integer asset units before decimal display.

Explorer locator: displayed event position for repeat inspection.

Attribution boundary: event participants are addresses, not identified humans.

Historical example

Ethereum mainnet, transaction 0x479e5dc5e1950916f29f1b3897c4158b94882339312da76373c496ce6c46d9fd, indexed block 10935968, rendered timestamp 2020-09-26T03:55:41Z. Pool 0xb4e16d0168e52d35cacd2c6185b44281ec28c9dc sends to 0x8cc757bc682e718d2f0264c1fcd3269eccf8214e. Raw amounts: 92255858879 USDC units and 262329864091228143654 WETH units; rendered equivalents 92,255.858879 USDC and 262.329864091228143654 WETH. Exact token addresses, event topic/data and indexed Burn/transfer locators are frozen. This is an actual historical indexed event, not a fictional launch.

Visual specifications

Historical signal timeline for indexed block 10935968 with rendered LP redemption/Burn/outflow locators and exact raw/display amounts. Put migration context and native proof gaps in separate boxes; no fraud badge or USD loss estimate.

Caption: Historical explorer-documented withdrawal; fraudulent intent and human identity are not established.

SPECIFICATION_ONLY — the rendered visual has not been produced or independently reviewed.

What the evidence proves

OBSERVED at the explorer boundary: the rendered successful transaction, exact pool/asset locators, timestamp and matching Burn/outflow amounts. Local decoding reproduces the raw integers and stated decimal displays.

What the evidence does not prove

No independent native inclusion/header, complete pool withdrawal fraction, subsequent destination accounting, human identity, theft, criminal intent or global safety is established. Decoded migration context is not a full independent benign-purpose proof either.

Common mistakes

Calling every Burn a rugpull; using current USD valuation as historical movement value; assigning a human from the explorer label; claiming complete migration custody from one transaction.

Practical exercise

Decode the two Burn data words using the frozen verifier, match them to transfer amounts, and prepare two conclusions: one about withdrawal and one about fraud. Include one unresolved migration dependency.

Show worked correction

The first data word decodes 92255858879; the second 262329864091228143654. They match the rendered USDC/WETH outflows from the exact pool to the recorded destination. Conclusion 1: “The frozen explorer record supports a historical liquidity withdrawal at the stated indexed event boundary.” Conclusion 2: “Fraudulent intent, theft and human identity are not established by this package.” Destination custody/post-migration accounting remains unknown; neither fraud nor a complete benign migration verdict follows. Native receipt/header verification would strengthen chain provenance but would still not by itself establish intent.

Checklist

  • Use exact transaction/pool/token identifiers.
  • Match Burn and transfer raw amounts.
  • Retain rendered/indexer provenance limits.
  • Separate withdrawal from identity, motive and legal conclusions.

Summary

The real indexed withdrawal has inspectable identifiers and amount correspondence, but those technical records do not settle an allegation of fraud.

Summary

  • An actual withdrawal can be supported without a fraud conclusion.
  • Raw units and display decimals need separate provenance.
  • Migration context does not remove destination-accounting gaps.

Next lesson

P13-L04

Tools

Use the named ZECOIN tool only as an evidence-reading context. This lesson creates no tool output, account session or entitlement. Offline exercise; do not sign, deploy, approve or fund anything.

Sources & claim boundaries

  • WITHDRAWAL: Historical rendered withdrawal transaction — Rendered Burn locator 15 and corresponding token outflows 12/13, transaction/height/time; source is an indexed explorer rendering, not independent native capture. Boundary: Bounded field transcription; cached web rendering possible. No independently captured native receipt/header, block hash, complete migration trace or human identity.
  • POOL: Uniswap v2 pools — LP tokens represent pool participation; withdrawal mechanism is separate from motive or fraud. Boundary: Mechanism documentation only; original illustrative values are stipulated, not observations. Historical records have separately frozen provenance and explicit collection gaps.

Evidence classifications

HISTORICAL — event dates and retrieval dates are separate. See frozen package and collection gaps.

Observation date

2026-10-02 (retrieval date; not event time)

Content version

1

Review date

null

Review status

needs_review

Visual specifications

P13-L03-V01

SPECIFICATION_ONLY · HISTORICAL

Differentiate documented withdrawal from unsupported fraud attribution

Historical explorer-documented withdrawal; fraudulent intent and human identity are not established.

Historical signal timeline for indexed block 10935968 with rendered LP redemption/Burn/outflow locators and exact raw/display amounts. Put migration context and native proof gaps in separate boxes; no fraud badge or USD loss estimate.

Historical signal timeline for indexed block 10935968 with rendered LP redemption/Burn/outflow locators and exact raw/display amounts. Put migration context and native proof gaps in separate boxes; no fraud badge or USD loss estimate.

Stack observations, assumptions, gaps and conclusion at 390 px; retain full IDs and a complete text equivalent. Any wide table scrolls locally.

Prose may follow RTL; IDs, quantities and time axes remain LTR. Preserve dependency direction.

P13-L03-WITHDRAWAL-20200926-v1

Sources & claim boundaries

WITHDRAWAL · EXPLORER_RENDERED_CHAIN_RECORD

Historical rendered withdrawal transaction

Supported claim
Rendered Burn locator 15 and corresponding token outflows 12/13, transaction/height/time; source is an indexed explorer rendering, not independent native capture.
Verification boundary
Bounded field transcription; cached web rendering possible. No independently captured native receipt/header, block hash, complete migration trace or human identity.
Checked at
2026-10-02
Open primary source
https://etherscan.io/tx/0x479e5dc5e1950916f29f1b3897c4158b94882339312da76373c496ce6c46d9fd

POOL · PRIMARY_DOCUMENTATION

Uniswap v2 pools

Supported claim
LP tokens represent pool participation; withdrawal mechanism is separate from motive or fraud.
Verification boundary
Mechanism documentation only; original illustrative values are stipulated, not observations. Historical records have separately frozen provenance and explicit collection gaps.
Checked at
2026-10-02
Open primary source
https://developers.uniswap.org/docs/protocols/v2/concepts/pools

Dataset provenance

id: P13-L03-WITHDRAWAL-20200926-v1

dataStatus: HISTORICAL

observedAt: 2026-10-02

timeBasis: Explorer-rendered 2020 blocktimestamp;2026 public-rendering extraction time separate

source: docs/academy-2/datasets/p13/withdrawal.json

scope: Bounded explorer event fields; no native receipt/header or human/intent proof.

Test your reasoning

P13-L03-Q1 · Which conclusion does the package support most directly?
P13-L03-Q2 · Why omit current USD panels from the movement amount?
P13-L03-Q3 · What does decoding the Burn data establish?
P13-L03-Q4 · The outer call is decoded migration. What remains unknown?
P13-L03-Q5 · Which evidence boundary must stay with the report?