At 18:07 UTC, Sui processed 1,924 eligible transactions. Most of the minute looked like order-book housekeeping: among the 1,894 rows with a usable behavior claim, 500 placed limit orders, 483 cancelled orders, and 220 updated prices. Together, those three behaviors accounted for 1,203 of 1,894 semantically classified rows.
The financial anomaly came from elsewhere. Sender-boundary holding evidence recorded a net inflow of 2,077,853.350842547 SUI across 802 transactions. One transaction, BJZvi3vh, accounted for +646,014.845459804 SUI—about 31% of that minute-wide SUI total—alongside +577,504.559125 USDC and +2.455285333 CETUS. The frozen roster flags that SUI movement as roughly 158 times the corpus’s 99th-percentile per-transaction movement. These are boundary movements, not prices, profit, or proof of who ultimately benefited.
The outlier was a staged liquidity-position workflow
BJZvi3vh was sent by 0xdc75a495…370c1a at checkpoint 300528395. Its five-step shape alternated two typed-coin construction calls with two reward-collection calls, then invoked a position-closing call. The transaction was not marked failed, and its detail records the sender-boundary changes above, but it does not attribute each returned asset to a particular call. The safest reading is therefore a large position-management and reward-collection attempt with substantial observed boundary inflows—not a proven payout or gain.
This was not an isolated label in the minute: 34 of the 1,894 behavior-classified rows were identified as close-liquidity-position. Taken together, those rows carried +2,100,511.568280681 SUI and +1,613,444.104948 USDC in holding evidence. The same minute also recorded +1,616,415.30935 USDC net across 58 transactions. The concentration makes liquidity-position maintenance the clearest explanation for the money movement, while leaving the exact economic outcome unresolved.
The dominant order activity was repetitive and tightly packed
The leading sender, 0xcde6dbe0…6c0e04, submitted 534 of 1,924 eligible transactions. That address is an on-chain identity, not an established person, company, or bot. Its activity included both placement and cancellation workflows. For example, HttGRtoM generated a DeepBook owner proof and passed it to a limit-order call with 0.39841 xBTC and a submitted resting price of 63,251 USDC per xBTC. The evidence identifies the order parameters but does not establish that the order entered or remained on the book.
The cadence was extremely compressed: the median gap was 0 ms, the 90th-percentile gap was 211 ms, and the longest idle period was 446 ms. There was a run of 456 consecutive transactions without an execution error. That rhythm is consistent with batched or automated execution, but it does not establish the operator’s identity or intent. Of the 1,924 transactions, 485 were sponsored, meaning a different gas owner paid for them.
Failures were present but not the story
Only 50 of 1,924 eligible transactions reported execution errors, a 2.60% failure rate—below the frozen corpus rate of 8.36%. Ten failures had no recorded abort site; eight stopped at a balance-splitting call, and another eight stopped while returning a flash-loan quote.
9e3s3Xza shows the distinction clearly. It attempted a shared reward-pool distribution and aborted at pool::distribute_rewards. Its application effects were rolled back, leaving only a 0.000129184 SUI gas/holding outflow. Sui’s transaction model is all-or-nothing for aborted application effects, while gas is still charged ([Sui’s system paper](https://docs.sui.io/paper/sui.pdf)). The row therefore proves an attempted distribution, not a completed reward transfer.
The minute was highly explainable overall: 1,820 of 1,924 rows were structurally classified, but that does not mean they succeeded. The 50 failures and the 33 rows marked unknown are separate facts. The main finding is the contrast between repetitive order maintenance and a small set of position-management transactions carrying most of the observed SUI inflow.
For a closer look, start with BJZvi3vh, compare it with the DeepBook placement HttGRtoM, and inspect the failed reward attempt 9e3s3Xza. The leading sender is 0xcde6dbe01902be1f200ff03dbbd149e586847be8cee15235f82750d9b06c0e04; the central reusable patterns are sui/close-liquidity-position/roster-f0137/v1 and sui/place-limit-orders/deepbook-owner-proof/v1.