SOL/SOL: the Cyrillic counterfeits flooding Solana with $170 billion of fake volume, run on a UTC+3–6 clock.
Someone deployed counterfeit copies of SOL, BTC, USDC, USDT and TRX on Solana, spelling each symbol with Cyrillic letters that render identically to the real thing. Then they traded the counterfeits against each other, in pools where both sides are fake, until the machine had printed $170 billion of volume from 56 wallets. Almost no real money ever touched it. The point is what happens off-chain: aggregators indexed the fake price, and wallet UIs will happily tell you a bag of counterfeit SОL is worth a hundred dollars a coin.
01 · The trick, in one glyphTwo letters that are not the same letter
Look at these two symbols: SOL and SОL. They render the same in most fonts — which is exactly the trick, and why we have to show you the bytes instead. Put each letter's Unicode code point under it and the forgery gives itself away:
The two tickers are pixel-identical on screen, and the middle letter of the second is a different character from a different alphabet. Paste it into a Unicode inspector and it decodes as Cyrillic O, the letter that starts Russian words like озеро. To a human eye scanning a wallet, a DEX screener or a token list, the two read as one symbol. To every piece of software that matches tokens by string, they are two assets.
That one glyph is the whole scheme. Deploy a token whose symbol is SОL, and no filter that blocks the word "SOL" will catch it, while every human who sees it will read it as Solana. The same trick built the rest of the family we found: ВТС and WВТС for Bitcoin, USDС for USD Coin, USDТ for Tether, ТRX for Tron, ЕТН for Ether. We have caught this alphabet before: our address-poisoning investigation traced a fake Tether on Ethereum whose ticker hides a Cyrillic Dze and Te, airdropped to over a million addresses. This time we pulled 30 days of DEX trades through Bitquery MCP and traced the whole trading cluster behind the alphabet.
02 · A market where both sides are fakeCounterfeits quoting counterfeits
You would expect a fake token to trade against a real one, fishing for victims. Mostly, these don't. The fake SОL trades in an Orca whirlpool against a fake USDT, a token whose symbol is plain ASCII but whose mint starts with a vanity usd2, where the real Tether mint starts with Es9v. The fake ВТС trades against the fake USDС. The fake USDС trades against the fake ТRX. It is a hall of mirrors: every "price" in it is quoted in an asset that is itself forged, so the machine can print any number it likes on both sides of every trade.
SoJh, BTCw, tRx, USYb and usd2 make the address itself read like the real asset.The busiest wallet, GcsrTAWg9vxeDLwcWScM6q513W8PYkXBViHofESDsGM1, traded 16 of the 21 fakes and made 18,331 trades in the window: buying from itself, selling to itself, around the clock for a month. Three helper wallets cover most of the rest. This is wash trading in its purest form: the same hands on both sides of the book, in a market nobody else attends.
03 · The SOL/SOL poolSelf-paired, so the pair reads like a typo
The oddest thing in the cluster is a pair of small whirlpools where the fake SОL trades directly against real wrapped SOL. On any UI that renders symbols, the pair shows as SOL against SOL, the same coin on both sides, which no honest market would ever list. One of the pools did thirteen trades for about twenty dollars total. These pools are tiny on purpose. Their job is to exist: they wire the fake into the real asset's liquidity graph, give it a price path a router can find, and finish the illusion that this SОL is just one more market for the coin you already own.
04 · The price is the productA counterfeit that tracks the real chart
Here is the detail that sets this apart from plain fake-volume spam. The fake SОL's price tracks real SOL, day after day, within a few dollars. That does not happen by chance in a closed loop; whoever runs it steers the wash trades to keep the fake chart glued to the real one.
The forged price does not stay on-chain, and that is the point. Data feeds that index every pool pick it up, and it shows up again in places with real logos on them. While digging we found auto-made "How to buy SОL" pages on Bitget Wallet's web listing for the fake mint, a Birdeye chart widget serving its candles, and a listing site quoting the fake usd2 Tether at a dollar. None of those sites is in on it. Their feeds simply ingest whatever trades, and this thing trades forty billion dollars a month.
05 · Where the real money wentAlmost nowhere — and that is the tell
We measured every trade in the cluster where the other side was real: real USDC, real wrapped SOL, real Tether. Over the full month, about $196K of real value went in, and about the same came out. Two thirds of that is a single wallet churning one pool in small, steady trades, which looks like the scheme's own float keeping a price anchor alive against real USDC. Most fake-versus-real pools saw less than fifty dollars of real money in a month.
So the DEX is not where this scam collects. Nobody of note is swapping real SOL for SОL. The theft happens wherever a fake that shows a price gets put in front of a victim: dropped into wallets so the balance reads as four figures, used as the "payment" side of an off-chain deal, or parked in a screenshot. It is the same play as address poisoning — the chain is used as a display surface, and the theft happens in the victim's eyes. The on-chain trading exists to print the price tag; we covered the twin trick, fake tokens named after real products, in the laptop token piece.
06 · This is an industryThe BSC farm with a vanity suffix
Solana is one branch. On BNB Chain we found 119 fake Tether contracts, every single one at a vanity address ending in 8888, spelling "USDT" out of Armenian, Lisu and Roman-numeral letters, ՍՏⅮꓔ, that fold to the real symbol in the eye. Together they printed about $804M of face-value volume in the month. The same factory pattern showed up in our wash-trading flip-hour piece: one template, deployed in batches, each copy thrown away when done.
07 · The quiet partZero tweets
Fake-volume pumps usually come with a social media blitz. This cluster is the opposite. We searched X for the fake SОL's mint address and found zero posts. No shills, no "gem" calls, nothing. A pump wants human eyes; a forgery wants to avoid them. Its audience is the machines: the indexers, the price APIs, the wallet balance screens. Total silence on social media is close to a tell for this kind of scheme.
Nobody has reported this cluster before. The closest prior art is generic: the FBI's warning about token-impersonation scams as a class, and a researcher's open escalation to Trust Wallet over a different set of fake USDT and SOL mints, still unresolved months later: "obvious scam tokens remain active in the wallet, while legitimate projects are rejected or delayed." That last one matters here. Even when someone hands a wallet vendor a list of fakes, the list stays live. None of the mints in this piece appears in any report we could find.
Every figure ran through Bitquery's trading data
Homoglyph screening across every token symbol on nine chains, pool-level pair reconstruction, cross-checked USD volume that refuses to price a one-sided loop, wallet clustering, and the real-versus-printed money split. All from multi-chain DEX trade data queried through Bitquery MCP. The trade feed flags every non-ASCII symbol, which is exactly the field this investigation is built on.
08 · The trading clockActive 02:00–19:00 UTC, silent 20:00–01:00
Wash bots can run around the clock. This one does not. Bucket the cluster's trades by hour of day and a human schedule appears: heavy activity from early morning UTC through the evening, then a hard stop. In the two hours before midnight UTC, the busiest wallet placed zero trades across the entire month, and the whole cluster managed nine.
One possible reading is that whoever runs this lives three to six hours east of UTC, a band that runs from Eastern Europe and western Russia through the Caucasus and Central Asia — which would sit naturally beside a Cyrillic keyboard, and beside the fake WВТС naming itself "VVrарреd" with two V's where a W should be, the classic tell of a layout with no native W. It stays a reading, and a weak one on its own. A bot can be scheduled to imitate any timezone, a server clock proves nothing about the person behind it, and Cyrillic letters are simply what this attack is made of, chosen for their shapes rather than their language. The activity clock is consistent with that region; it does not identify anyone or anywhere.
09 · Screen it yourselfThree checks before you trust a symbol
For anyone building token lists, wallet UIs or screeners on DEX trade streams, the fix is cheap: fold symbols to their Latin skeleton before display, resolve assets by mint address, and treat a price that only exists inside a closed loop of forged quotes as no price at all.
This is not financial advice. This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, tax, or investment advice, and nothing in it is a recommendation, solicitation, or offer to buy, sell, or hold any token.
The findings characterize on-chain transaction patterns and inferences drawn from them. They are not assertions that any specific person or entity engaged in unlawful conduct, and should not be read as accusations of criminal or regulatory wrongdoing. Token symbols and contract addresses are referenced solely to make the on-chain analysis reproducible. References to third-party websites that surfaced auto-generated pages for these tokens describe automated indexing pipelines, and are not claims that those companies participated in, endorsed, or were aware of the activity described.
On-chain figures (wallet counts, volumes, prices, and timestamps) were reconstructed from DEX trade data over a 30-day window and may be incomplete or subject to revision as additional data becomes available. USD figures attached to trades between counterfeit assets are nominal values printed by the scheme itself and do not represent real economic value; the article's methodology section explains how cross-checked figures were derived.
The timezone discussion in this article is speculative and circumstantial. It infers a possible clock offset from the timing of on-chain activity, and nothing more. Automated systems can be scheduled to imitate any timezone, server time reflects infrastructure rather than people, and the use of Cyrillic or other non-Latin characters indicates only the mechanics of a homoglyph attack, never the language, nationality, ethnicity, or location of any person. No statement in this article attributes this activity to any country, region, or group, and none should be inferred.
Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and product names are the property of their respective owners.
Resolve tokens by address, never by symbol
The data that exposed this cluster is the same data that protects a product from it: every DEX trade on nine chains with mint addresses, cross-checked USD values, and a non-ASCII flag on every symbol, in real time.