And this was the same with all of the contracts I checked manually: all of the start() and withdrawal() calls lead to the internal transfer to the wallet hardcoded in the scam sample code. They all lead to our $2mln wallet — in the graph below you can see that 3 accounts mentioned in the scam contracts code all route the funds to the same wallet: The $2m account seems like an endpoint for all of the fraudulent money made inside the scheme — it only outputs funds to a couple ByBit and A LOT of Stake.com wallets, then probably laundering the money through betting off-chain.