Skip to content

[Operational recovery] 16.7 ETH remains at a generated deposit EOA with nonce 0; deposit was never bridged #635

Description

@xiongmaozhanjiangshi

Summary

I am trying to route an operational recovery case to the component that controls an Ethereum deposit address generated during a production 1Click / OmniBridge route.

The user deposited exactly 16.7 ETH to the address returned by the signed 1Click quote. The Ethereum transaction succeeded within the quote deadline, but the deposit address has never sent an outgoing transaction and the 1Click status still says PENDING_DEPOSIT.

This is not a request for code-debugging support. I am asking the OmniBridge maintainers to confirm whether this address belongs to the OmniBridge / Chain Signatures / MPC derivation path and, if so, route it to the relayer or keyholder team that can safely return the funds.

Reproducible on-chain facts

  • Deposit address: 0xFD0418D3D663f21b503Ca3Ee6ad72C1e760926EC
  • Deposit transaction: 0x74d91c7f07d1ceaa49a4b6a05d8289eed17cd2203eb3ca295211cda3e26ded0c
  • Deposit value: exactly 16.7 ETH
  • Transaction receipt: success (status=1)
  • Current address balance: exactly 16.7 ETH
  • Current transaction count / nonce: 0
  • Current contract code: 0x
  • Configured refund address: 0x60c2cddb1ac686c5f7e681c898062131af0d3458

Public links:

1Click status

Fresh read-only status check on 2026-07-12T14:21:36Z:

  • Status: PENDING_DEPOSIT
  • API updatedAt: 2026-07-01T13:50:52.122Z
  • Deposited amount: null
  • Origin-chain transaction hashes: []
  • NEAR transaction hashes: []
  • Intent hashes: []
  • Destination-chain transaction hashes: []
  • Refunded amount: 0
  • Latest correlation ID: e16d10cd-01c7-4ae7-b5c2-3f43d9d3f64f

The deposit address was returned by the signed 1Click quote at approximately 2026-04-21T09:39:46Z, and the on-chain deposit landed approximately 37 seconds later. Earlier submission of the transaction hash to the 1Click deposit endpoint did not associate the transaction.

Existing 1Click incident: defuse-protocol/one-click-sdk-typescript#6

NEAR support reference: Ticket 22767

Requested maintainer action

  1. Confirm whether 0xFD0418D3D663f21b503Ca3Ee6ad72C1e760926EC was generated or controlled by the OmniBridge / Chain Signatures / MPC deposit flow.
  2. If yes, route this privately to the relayer/MPC/keyholder operator that can authorize a safe sweep and refund to the configured refund address.
  3. If no, identify the subsystem or repository that owns this deposit-address path so the issue can be routed correctly.
  4. Preserve relevant derivation, relayer, scanner, and MPC request logs while the incident is investigated.

Because the original swap quote expired months ago, the requested remedy is return of the 16.7 ETH to the configured refund address, not execution of the stale BTC quote.

I can provide the complete signed quote response and raw 1Click API status response through a private channel.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions