1
Heterogeneous Cross-Chain Transaction Tracing for Solana Bridges via Candidate-Set Selective Decision
arXiv:2609.11413v1 [cs.CR] 10 Sep 2026
Wenjie Dou, Zheng Che∗ , Meng Shen, Hanbiao Du, Qing Li, and Yan Qiang
Abstract—Solana is a rapidly growing high-throughput blockchain platform that has attracted substantial liquidity and user activity. However, this expansion has also drawn the attention of illicit actors, who frequently leverage cross-chain bridges to route illicit funds onto Solana to obfuscate transaction lineage. Unlike EVM-compatible platforms, Solana features distinct execution dynamics and lacks standard event logs, creating severe semantic gaps that prevent existing tracing methods from reliably correlating cross-ledger transactions. In this paper, we formalize four types of Solana-bound cross-chain transaction modes and propose a candidate-set selective decision-based tracing method called SolTracer. SolTracer maps disparate execution semantics into a unified event space and employs candidate-set selective decision-making to reliably associate target transactions while abstaining when valid targets are absent. Extensive experiments demonstrate that SolTracer outperforms state-of-the-art (SOTA) methods across three representative scenarios: closedworld association, open-world association, and cross-source-chain generalization. In particular, under the challenging open-world setting with a 50% TA ratio, SolTracer improves the F1 score by 20.16% over the strongest SOTA baseline. Utilizing SolTracer, we conduct an empirical analysis on real-world cross-chain transfers to investigate ecosystem dynamics. Our analysis explores the stark count-value divergence across bridge mechanisms, the prevalence of cross-asset shifts, and the decoupling between onchain settlement and explorer visibility. Index Terms—Cross-chain bridges, Solana, public blockchain, transaction tracing, selective decision.
I. I NTRODUCTION Driven by its ultra-low transaction fees and sub-second confirmation latency, Solana has rapidly emerged as a dominant high-throughput public platform. According to CoinMarketCap [1], as of August 2026, Solana ranks among the top five cryptocurrencies globally by market capitalization. Furthermore, its daily decentralized exchange (DEX) trading volume has frequently surpassed that of the Ethereum, underscoring its pivotal role in the modern digital asset ecosystem. Concurrently, the rapid proliferation and adoption of crosschain bridge protocols have provided illicit actors with new avenues for money laundering and asset flight. Given Solana’s massive liquidity and high throughput, cybercriminals frequently utilize its infrastructure to obfuscate transaction traces. For instance, in the Solana drainer campaigns targeting thousands of wallets, malicious actors exploited AllBridge to Wenjie Dou, Zheng Che, Qing Li, and Yan Qiang are with the School of Software, North University of China, Taiyuan 030051, China (e-mail: [email protected]; [email protected]; [email protected]; [email protected]). Meng Shen and Hanbiao Du are with the School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing 100081, China (e-mail: [email protected]; [email protected]). ∗ Corresponding author: Zheng Che ([email protected]).
Event Logs
Event Logs
From, To, Token Timestamp, Amount, … …
From, To, Token Matched Timestamp, Amount, … …
Source Tx
Destination Tx
(a) Homogeneous cross-chain TX Event Logs From, To, Token Timestamp, Amount, … … Source Tx
Execution States Semantic Gap
Instructions Balance Deltas Invocation… …
Destination Tx
(b) Heterogeneous cross-chain TX Fig. 1. Comparison of transaction tracing between homogeneous and heterogeneous cross-chain transaction
bridge over one million USD of stolen assets directly from Solana to Ethereum [2], [3]. Similarly, during the BingX exploit, attackers routed stolen funds onto Solana via deBridge, performed token swaps to disrupt asset lineage, and subsequently funneled them through multi-chain bridging services [4]. Due to fundamental structural discrepancies between the source and target chains—such as heterogeneous account state models and execution logic—tracing transactions across these platforms becomes exceptionally difficult. As illustrated in Fig. 1, these architectural differences prevent heterogeneous cross-chain transactions from being easily correlated in the way homogeneous ones are. Recent studies [5]–[11] have investigated cross-chain transaction tracing primarily on Ethereum Virtual Machinecompatible (EVM-compatible) blockchains by correlating transaction attribute similarities or event logs between source and target chains. However, existing methods suffer from two fundamental challenges: (1) Cross-Chain Heterogeneity. Existing methods rely on uniform parsing schemes tailored for homogeneous receipts. In heterogeneous chains like Solana,
2
In this paper, we focus on analyzing and tracing Solanabound cross-chain transactions across heterogeneous ledgers. To address the semantic gap stemming from disparate blockchain execution models, we first identify and summarize four types of Solana-bound cross-chain transaction modes based on their underlying settlement mechanisms. To achieve reliable association across heterogeneous chains, we propose SolTracer, a cross-chain tracing method based on candidate-set selective decision, which maps disparate transaction semantics into a unified semantic event space and performs selective association over the candidate set through multi-field consistency verification. Finally, to gain deeper insights into the Solana cross-chain ecosystem, we conduct an empirical analysis to uncover critical security and observability characteristics within the Solana bridge ecosystem. We summarize the main contributions as follows: We identify and summarize four transaction modes for Solana-bound cross-chain transactions, i.e., Message Redemption, Pool Settlement, Solver Fulfillment, and BurnMint transactions. This abstraction formally characterizes the funding workflows and execution dynamics of various bridge mechanisms on Solana. • We propose SolTracer, a cross-chain tracing method based on candidate-set selective decision, which maps disparate transaction semantics into a unified semantic event space and performs selective association over the candidate set through multi-field consistency verification. • We evaluate the performance of SolTracer by comparing it to six SOTA methods, including AttrMatch [8], EntityMatch [8], MultiMatch [11], CONNECTOR [5], ABCTRACER [6] and ConneX [7]. SolTracer achieves the highest F1 scores in closed- and open-world settings. • Based on the associated cross-chain trasactions, we conduct an empirical analysis to examine their count–value divergence, cross-asset shifts, target observability gaps, and mechanism-dependent association reliability, followed by a summary of several key findings.
EVM
Solana
Tx Queue (FIFO)
Parallel Concurrency
Tx1
Accounts: [Acc1, Acc2]
1. Execution
Tx2 Track 1
Track 2
Track 3
Tx3 TxA TxB Global State Lock
Global state
Overlap
TxC
Trace Signal
2. Record
the absence of standard event logs and the divergence of execution models lead to severe semantic gaps that prevent direct field alignment. (2) Reliable Association. Existing methods often assume that each source-chain transaction has a unique and directly identifiable counterpart on the target chain. This assumption does not always hold in real-world bridge scenarios, where asynchronous processing, cross-asset solver settlement, or unexecuted transfers may break the oneto-one correspondence between source and target transactions [12]. Consequently, forcing such deterministic alignment can introduce substantial spurious associations and lead to a high false-positive rate.
Route
wormhole
Recipient ATA...cedf Amount
100.00
Asset
USDC
Event
transfer
Trace Signal Program: complete
Asset: USDC
Amount: 100.00
role: recipient
Recipient: ATA(…ce)
......
Fig. 2. Comparison of execution models and visible artifacts between EVM and Solana.
II. BACKGROUND AND R ELATED W ORK In this section, we first introduce the background of crosschain transactions and outline the key differences between EVM and Solana. We then review existing research on crosschain transaction tracing.
•
The remainder of this paper is organized as follows. Section II reviews background and related work. Section III formalizes the cross-chain tracing problem, and Section IV defines the four transaction modes. Section V presents SolTracer, followed by its experimental evaluation in Section VI. Section VII discusses empirical insights into the Solana bridge ecosystem, and Section VIII concludes the paper.
A. Cross-Chain Transactions Due to the lack of shared state across isolated blockchains, a cross-chain transaction fundamentally relies on the interaction among three key components: the source chain, the cross-chain bridge, and the target chain. 1) Source Chain. The cross-chain transfer begins on the source chain, where a user submits a transaction to record their transfer intent—such as the target chain, recipient, asset, and amount. Depending on the bridge mechanism, this step commits the initial state transition by locking, escrowing, or burning tokens, and emits event logs or state changes that serve as the origin record [13]. 2) Cross-Chain Bridge. As the intermediate coordination layer, the bridge validates the validity of the source-chain transaction and relays the authorization to the destination network. Once the source transfer reaches finality, its verification mechanism verifies the state change through external validators, optimistic windows, or cryptographic proofs, and then issues a verified message, attestation, or proof for crossledger delivery [6]. 3) Target Chain. The final settlement occurs on the target chain, where a relayer or user submits the verified payload to the destination bridge contract. After validating the authorization and preventing replay, the contract executes the final state transition to deliver funds to the recipient, which includes actions such as releasing escrowed assets, minting tokens, or triggering local contract calls.
3
TABLE I S UMMARY OF E XISTING S TUDIES ON C ROSS -C HAIN T RACING Category
Methods
Data Acquisition
Task
Methodology
Cross-Chain Heterogeneity
Reliable Association
Centralized Bridge Tracing
Yousaf et al. [8] CLTracer [9] Hu et al. [10]
ShapeShift API DE APIs Instant CE Service
Transaction association Account association Account association
Heuristic analysis Heuristic analysis Heuristic analysis
✓ ✓ ✗
✗ ✗ ✗
Yan et al. [11] CONNECTOR [5] ABCTRACER [6] ConneX [7]
Public Ledgers Public Ledgers RPC Services RPC Services
Transaction association Transaction association Transaction association Transaction association
Heuristic analysis Machine learning Deep learning LLM and Heuristics
✗ ✗ ✗ ✗
✗ ✗ ✗ ✗
SolTracer
RPC Services & APIs
Transaction association
Selective Decision
✓
✓
Decentralized Bridge Tracing
B. Differences Between EVM and Solana EVM and Solana exhibit fundamental differences in generating and exposing cross-chain trace evidence. We examine these differences from two primary perspectives: State Execution and Transaction Records, as summarized in Fig. 2. 1) Execution View. The EVM applies smart-contract transactions as ordered updates to shared global state, whereas Solana organizes program execution around the accounts declared by each transaction. Solana can execute transactions concurrently when their account-access sets do not conflict [14], so its execution relation is constrained by account dependencies rather than a single global-state transition path. 2) Record View. Transaction records are the ledger-visible data used to extract tracing evidence. While EVM smart contracts encapsulate bridge semantics within structured, ABIdecoded event logs embedded directly in transaction receipts, Solana fundamentally lacks such unified event logs and fragments bridge semantics across invoked programs, account roles, inner instructions, and balance deltas. Consequently, an observer cannot rely on a single receipt but must actively reconstruct and aggregate these disparate execution fragments before associating source- and target-side transactions.
C. Related Work In this section, we systematically review recent research on the cross-chain transaction tracing in cryptocurrencies. We categorize existing research into two categories based on the bridge architecture: centralized bridge (CE bridge) tracing and decentralized bridge (DE bridge) tracing, as shown in Table I. 1) CE bridge tracing. Centralized bridges execute asset exchanges off-chain, exposing only decoupled deposit and withdrawal transactions on the public ledgers without intermediate matching traces. Hence, this type of research heavily depend on service-exposed APIs to collect operational data and apply heuristic rules over transaction metadata for association. Yousaf et al. [8] combine ShapeShift records scraped from a public API with transactions from eight blockchains and use temporal and value heuristics to recover deposit–withdrawal flows. Zhang et al. [9] replaces real-time monitoring with account-relationship-based historical transaction discovery and cross-ledger clustering. Hu et al. [10] collect instant exchange
services through aggregator sites and controlled user interactions, then correlate deposits and withdrawals using temporal and pricing constraints. 2) DE bridge tracing. Decentralized bridges execute transfers through on-chain smart contracts, providing verifiable and auditable ledger records. Hence, this type of research mainly exploit these transparent contract traces, event logs, and transfer values to reconstruct cross-chain pairs. Yan et al. [11] associate Ethereum–Polygon transfers using shared user accounts alongside temporal, value, and token constraints. Lin et al. [5] identify source-side deposits from contract traces and correlate target-side withdrawals via bridge execution logs. To uncover less obvious relationships, Lin et al. [6] apply named-entity recognition and information retrieval over event logs to capture implicit cross-chain cues.More recently, Liang et al. [7] leverage large language models for automatic semantic key–value extraction, validating candidate associations via value checks. 3) Summary. The limitations of existing methods are primarily reflected in two aspects. First, existing methods rely on homogeneous ledger assumptions, extracting explicit cues primarily from ABI-decoded event logs and structured transaction receipts. These parsers fail on heterogeneous ecosystems like Solana, where standard event logs are absent and execution semantics are scattered across accounts, inner instructions, and balance deltas. Second, current association heuristics enforce a rigid one-to-one closed-world mapping without a candidateset-level reject option. Consequently, when target transactions are absent due to delayed relaying, solver batching, or unexecuted transfers, existing ranking schemes inevitably select the top-scoring distractor and produce false associations. III. P ROBLEM D EFINITION This paper focuses on tracing Solana-bound cross-chain transactions by addressing target-transaction observability gaps across heterogeneous execution models. Formally, given an observed source-side bridge-out transaction os ∈ OS on an EVM-compatible ledger, a protocol-compatible filtering mechanism first extracts a bounded candidate set C(os ) = {ot,1 , ot,2 , . . . , ot,k } ⊆ OT , where OT denotes the Solana target observation space. Let o∗ ∈ OT ∪ {⊥} represent the ground-truth Solana target transaction corresponding to os , where o∗ = ⊥ indicates that the cross-chain execution has
4
not settled on-chain or falls beyond the observation scope. Consequently, the candidate set is not guaranteed to contain a valid target (i.e., o∗ ∈ / C(os ) may occur) due to delayed relaying, solver batching, or unexecuted transfers. To achieve reliable tracing under target uncertainty, we model the association process via a selective decision function F (os , C(os )) ∈ C(os ) ∪ {⊥}, defined as: ( ôt , if Γ(os , ôt | C(os )) = 1, (1) F (os , C(os )) = ⊥, otherwise, where ôt = arg maxot ∈C(os ) S(os , ot ) is the top-ranked candidate evaluated by a heterogeneous semantic scoring function S(·), and Γ(·) ∈ {0, 1} is a selective decision rule that accepts the candidate only when its association evidence significantly dominates competing distractors. Based on this formulation, the design goals of our tracing system are twofold: 1) Heterogeneous Semantic Association: When the ground-truth target is present in the candidate set (o∗ ∈ C(os )), the objective is to reconstruct unified semantic features across disparate execution models such that the true target achieves the dominant matching score, yielding ôt = o∗ and F (os , C(os )) = o∗ . 2) Reliable Association: When a reliable association cannot be guaranteed—either because the ground-truth target is absent (o∗ ∈ / C(os )) or the candidate set exhibits high semantic ambiguity—the decision rule should reject all candidates (Γ(·) = 0) and output ⊥, thereby provably preventing falsepositive attributions. IV. S OLANA -B OUND C ROSS -C HAIN T RANSACTION M ODES In this section, we formalizes four Solana-bound transaction modes based on underlying funding topologies: Message Redemption Transactions, Pool Settlement Transactions, Solver Fulfillment Transactions, and Burn–Mint Transactions. For each mode, we characterize its execution workflow and analyze the observability gaps that hinder cross-chain correlation. The four transaction modes are illustrated in Fig. 3. Source Address
Target Address
1.Asset
3.Proof
2.Proof
4.Asset
Asset Flow
Message Flow
1.Asset
2.Asset
Bridge
Bridge
(a) MRT
(b) PST
1.Intent
2.Asset
4.Asset
3.Asset
5.Asset
Solver
1.Asset
Bridge
(c) SFT
2.Asset
Bridge (d) BMT
Fig. 3. Solana-Bound Cross-Chain Transaction Modes
A. Message-Redemption Transactions, MRT MRT operates on a message-verification workflow where a verified source-chain attestation is redeemed on Solana to
trigger a target-side release or minting operation (Fig. 3(a)). Representative implementations include Wormhole [15] and deBridge [16]. Under this mode, target-side evidence generally preserves source asset and amount semantics following asset mapping and decimal normalization. Due to Solana’s account architecture, the recipient is explicitly designated through a program-derived Associated Token Account (ATA) on the target chain. The main observability gaps arise from: Account Transformation. Heterogeneous account formats prevent direct comparison between the source recipient and the corresponding Solana token account. • Indirect CPI Visibility. Bridge programs transfer assets via Cross-Program Invocations (CPIs) to the Solana Program Library (SPL) Token program. Top-level instruction parsers only observe the root bridge invocation, requiring manual aggregation across inner instructions and balance deltas to recover the recipient and transferred amount. •
B. Pool-Settlement Transactions, PST PST executes cross-chain transfers by drawing liquidity from a shared Solana-side pool to pay the recipient (Fig. 3(b)). Representative implementations include Allbridge Core [17]and Stargate V1 [18]. The target payout amount frequently diverges from the initial source amount due to protocol fees, dynamic slippage, pool liquidity states, or intermediate conversions, resulting in route-dependent amount relations. The main observability gaps arise from: Amount Variation. Fees, slippage, and route-specific conversion can change the target payout, invalidating exact comparison with the source amount. • Shared-Pool Ambiguity. A pool may serve multiple transfers within the same observation window, producing several payouts that all fall within the same time window and amount tolerance. •
C. Solver-Fulfillment Transactions, SFT SFT operates under an intent-based paradigm where the source-chain transaction records a user’s target parameters, including the destination chain, recipient, requested asset, and minimum acceptable output (Fig. 3(c)). Independent thirdparty solvers or relayers fulfill these conditions on Solana directly using proprietary liquidity, as exemplified by deBridge DLN, Mayan Swift, and Across [19]–[21]. Consequently, the target settlement forms a decoupled execution rather than an on-chain continuation of the source fund flow. The main observability gaps arise from: Cross-Asset Fulfillment. Under cross-asset routes, the delivered asset may differ from the source asset, making raw asset equality an unreliable association signal. • Funding-Path Separation. Funds come from a solvercontrolled account rather than a bridge-controlled account. This removes direct asset-flow continuity and weakens account-based links, although intent or solver evidence may remain visible. •
5
D. Burn-Mint Transactions, BMT BMT completes cross-chain transfers by burning canonical tokens on the origin ledger and minting native target tokens on Solana upon presenting a cryptographically verified off-chain attestation (Fig. 3(d)). Representative implementations include Circle CCTP [22] and LayerZero Solana OFT routes [23]. While recipient identities and normalized values are generally preserved across chains, the authorizing attestation logic and the final minting execution are split across distinct transaction phases and data layers. The main observability gaps arise from: • Authorization-Evidence Separation. The attestation is produced off chain, while its payload and verification effects may appear on chain. Ledger-only analysis can therefore observe the mint without recovering the full provenance that authorizes it. • Mint-Candidate Ambiguity. Several mint operations with similar asset, amount, and timing attributes may occur within the same observation window, making time and value evidence insufficient to identify the intended target among competing mint candidates. Across the four modes, heterogeneous execution breaks source-to-target semantic continuity in four dimensions: recipient account representations, transferred amount dynamics, asset identity consistency, and authorization provenance. Consequently, existing heuristics that rely on static attribute alignments fail to generalize across heterogeneous bridges [8], [11]. Bridging these semantic gaps requires decoding Solana-specific CPIs, account roles, and off-chain attestations—concepts that cannot be captured by uniform EVMtailored heuristics—which motivates the design of SolTracer. V. T HE P ROPOSED S OLT RACER In this section, we propose SolTracer, a candidate-set selective decision method designed for tracing Solana-bound crosschain transactions across heterogeneous blockchains.
3) Candidate Selective Association. This module constructs a bounded candidate set for each source intent and scores candidate pairs using multi-field semantic consistency across time, asset, amount, and participant roles. It further incorporates a candidate-set-level reject option that dynamically assesses candidate separation, thereby achieving reliable association when the true target exists while provably abstaining from false attributions when the target is absent. B. Bridge Protocol Identification This module receives os and the Solana observation pool OT . Its primary objective is to determine whether the source observation is supported by the protocol knowledge base available to SolTracer and, if so, to decode the source intent parameters and retrieve protocol-compatible Solana evidence required by downstream modules. The protocol registry serves as a formal knowledge layer that can be extended via expert-guided specifications and semiautomated learning from protocol documentation and verified cross-chain transactions. Each protocol specification encapsulates stable invariants, including router and program identifiers, event topics, route directions, asset mappings, expected latency windows, amount transfer semantics, and participant account roles, without caching ground-truth target transactions. Formally, let Π denote the set of candidate protocol specifications. For each protocol q ∈ Π, SolTracer evaluates the rule-level compatibility of the observed source transaction os : Sq (os ) =
K X
wj I[ϕj (os ) |= rq,j ] ,
(2)
j=1
where ϕj (os ) denotes the j-th observed routing cue, rq,j is the corresponding matching rule for protocol q, and wj represents its assigned weight. SolTracer then identifies the best-matching protocol candidate: p = arg max Sq (os ).
(3)
q∈Π
A. Overview of SolTracer The main components of SolTracer are threefold, namely the bridge protocol identification module, the semantic event reconstruction module, and the candidate selective association module. The overview of the SolTracer is shown in Fig.4. 1) Bridge Protocol Identification. This module identifies the underlying bridge protocol from source-chain routing cues and decodes the initial cross-chain intent, including route direction, asset mappings, and participant parameters. It also retrieves protocol-compatible transaction fragments from the Solana while admitting only supported transfers, thereby filtering out incompatible observations prior to candidate construction. 2) Semantic Event Reconstruction. This module maps the disparate execution fragments of accepted transactions into a unified semantic event schema via mode-specific adapters. It systematically aggregates EVM receipts with Solana’s inner instructions, account roles, and balance deltas across the four transaction modes (MRT, PST, SFT, and BMT), producing standardized semantic events with full field provenance to serve as inputs for the candidate selective association module.
The identified protocol p is accepted if and only if Sp (os ) ≥ τproto . Otherwise, the module outputs the abstention symbol ⊥ to signify an unsupported transfer. Algorithm 1 summarizes this protocol identification and evidence retrieval workflow. Through this mechanism, the module decodes key source intent parameters alongside compatible Solana execution traces Algorithm 1 Bridge Protocol Identification Input: Source observation os , protocol specifications Π, threshold τproto , observation pool OT Output: Decoded evidence tuple (p, ds , Dp ) or selective abstention ⊥ 1: p∗ ← arg maxq∈Π Sq (os ) 2: if Sp∗ (os ) < τproto then 3: return A BSTAIN(out-of-support) 4: end if 5: p ← p∗ 6: ds ← D ECODE S OURCE(os , p) 7: Op ← R ETRIEVE TARGET(OT , p) 8: Dp ← D ECODE TARGET F RAGMENTS(Op , p) 9: return (p, ds , Dp )
6
Bridge Protocol Identification
Semantic Event Reconstruction
Candidate Selective Association
Mode-Specific Adapters
Mode – Protocol Compatible Filtering
Bridge
tx
mayan
Data input
tx
wormhole debridge
.. .. ... ... . .
allbridge
…
circle
Source
Protocol-Guided parse
normalize
prov
Solana Candidate Ranking
Transaction Model mapping MRT
PST
SFT
BMT
↔
― ― ―
― ― ―
Rank 1
Δs
Rank 2 Rank 3
Raw data parse
Decoded Transaction
Source-chain TX route
···
asset
···
amount
···
recipient
···
···
···
Common Semantic Event Space Source-chain TX
Target-chain TX
route
route route route route Asset Amt. route
Target-chain TX transfer key … … …
mintTo key … … …
complete key … … …
message key … … …
Asset Amt.
Candidate Set Reject Option Rank 1 0x2ded ...93de7
S1
Selective Decision 3PNo7z ...mj6tV ✓ Association
× Abstention
role role role role role
role
s₁ s₂ s₃
recipient amount No cue Match√
asset role Diff .0 Match√
0
τ
1
Fig. 4. System overview of SolTracer, which consists of three modules, i.e., Bridge Protocol Identification, Semantic Event Reconstruction, and Candidate Selective Association.
(such as program IDs, account roles, and balance deltas). By enforcing protocol-level admission control prior to candidateset construction, SolTracer prunes unsupported or malformed transfers at an early stage, preventing incompatible noise from polluting candidate sets and mitigating false associations induced by forced matching. C. Semantic Event Reconstruction The identified protocol p determines the execution route and activates the corresponding mode adapter. For each observation o, the adapter integrates raw execution traces Exec(o) and state transitions State(o) into a unified semantic event: Ep (o) = Mapp (o, Exec(o), State(o)) = ⟨id, t, R, P, A, V, Φ⟩,
(4)
where Exec(o) captures transaction receipts, event logs, inner CPI trees, and program logs. State(o) records balance transitions (∆B = postBalances − preBalances); R, P, A, and V denote the route domain, participant roles, normalized asset identifier, and decimal-adjusted amount, respectively. Φ stores provenance metadata tracking underlying evidence layers. Algorithm 2 implements the semantic reconstruction across disparate transaction modes, projecting mode-specific execution fragments into a common semantic space. For MRT, the adapter unrolls inner CPI trees directed to the SPL Token program, resolves the program-derived ATA to the recipient, and normalizes decimal values. For PST, it extracts net balance deltas from State(o) to absorb pool fees and dynamic slippage, bounding the payout amount within route-specific intervals. For SFT, it parses intent-fulfillment logs to decouple intermediate solver funding accounts from actual recipients, accommodating cross-asset swaps. For BMT, it reconciles offchain attestation proofs with on-chain mintTo invocations across split execution phases. All adapters output the uniform schema Ep (o) for downstream candidate selective association.
Algorithm 2 Semantic Event Reconstruction Input: Obs. o, proto. p, traces Exec(o), state State(o) Output: Semantic event Ep (o) = ⟨id, t, R, P, A, V, Φ⟩ 1: E ← InitHeader(o), Φ ← ∅, m ← GetMode(p) 2: if m = MRT then 3: (P, A, V) ← ExtractCPI_ATA(Exec(o), State(o)) 4: Φ ← {CPI, ATA} 5: else if m = PST then 6: (P, A, V) ← ExtractPoolDelta(State(o), p) 7: Φ ← {BalanceDelta, Fee} 8: else if m = SFT then 9: (P, A, V) ← ExtractSolverPayout(Exec(o), State(o)) 10: Φ ← {OrderIntent, SolverTrace} 11: else if m = BMT then 12: (P, A, V) ← ExtractMintProof(Exec(o)) 13: Φ ← {Attestation, MintCPI} 14: end if 15: return E ∪ ⟨P, A, V, Φ⟩
D. Candidate Selective Association The third module uses the common events to build the candidate set defined in Section III. Given os and the accepted protocol p, SolTracer applies protocol-compatible filtering to the Solana observation pool: C(os ) = {ot,i ∈ OT | matchp (Ep (os ), Ep (ot,i )) = 1} , (5) where matchp checks the route and time window, mapped or expected target asset, mode-specific amount relation, and recovered participant roles. It therefore supports fee-adjusted PST payouts and cross-asset SFT fulfillment without enforcing strict equality over raw assets and amounts. An empty set indicates candidate-space abstention rather than a ranking failure. Let C denote C(os ) in the rest of this subsection. For every candidate pair retained after filtering, SolTracer compares the reconstructed events by time distance, normalized or expected amount, direct or mapped asset agreement, participant roles, mode-specific evidence, and provenance completeness. A pairwise scorer ranks the candidates as ot,(1) , ot,(2) , . . .. Ranking
7
alone is insufficient because every nonempty candidate set has a top-ranked element. SolTracer therefore applies a lightweight candidate-set-level reject option. Let e z(C) denote the standardized candidate-set vector containing the top score, score separation, time and amount consistency, and asset, recipient, and semantic-role consistency. A logistic model estimates whether the candidate set supports a valid association: Pset (C) = σ wTe z(C) + b , (6) where w and b are learned jointly from target-present and verified target-absent candidate sets using class-balanced training. The operating threshold τ is selected on calibration data. This candidate-set score implements the reliability rule in Eq. (1) via Γ(os , ôt | C) = I[Pset (C) ≥ τ ]. When C ̸= ∅ and Pset (C) ≥ τ , the decision function F returns the top-ranked candidate ôt . Otherwise, it returns ⊥. The recorded reason distinguishes candidate-space abstention, where C is empty, from candidate-set-level abstention, where a nonempty set fails to reach τ . Consequently, selective association prevents forced false-positive attributions without changing within-set ranking. VI. P ERFORMANCE E VALUATION In this section, we conduct extensive experiments to evaluate the effectiveness of SolTracer. We first construct the dataset by exploiting real-world EVM-to-Solana cross-chain records across representative bridge protocols. Secondly, we introduce the implementation details, followed by a sensitivity analysis. Thirdly, we thoroughly compare SolTracer with the SOTA methods across three typical scenarios: closed-world, openworld and generalization. Finally, we perform ablation studies to assess the contributions of each module within SolTracer.
TABLE II S UMMARY OF THE C OLLECTED AND L ABELED DATASET.
Bridge
Raw Data
Ethereum (CP/NCP)
Arbitrum (CP/NCP)
Base (CP/NCP)
Polygon (CP/NCP)
Wormhole Allbridge deBridge Circle
5,977 1,480 1,600 29,260
1,082/32,460 68/2,040 279/8,370 795/23,850 182/5,460 182/5,460 997/29,910 200/6,000 200/6,000 1,495/44,850 385/11,550 477/14,310
196/5,880 182/5,460 200/6,000 162/4,860
Total
38,317
4,369/131,070 835/25,050 1,138/34,140 740/22,200
orders and Solana fulfillment transactions yields 1,597 valid source–target pairs, including 997 from Ethereum and 200 from each of Arbitrum, Base, and Polygon PoS. • Circle: We use Circle CCTP as the representative BMT product and index 29,260 source-side burn records using Dune Analytics, Circle Iris, and CCTP program histories. After source-chain filtering, message-level deduplication, and semantic consistency verification against Solana receive-and-mint transactions, 2,519 valid burn– mint pairs are retained, including 1,495 from Ethereum, 385 from Arbitrum, 477 from Base, and 162 from Polygon PoS. As summarized in Table II, each verified source–target association is treated as a correlated pair (CP). For each CP, we construct 30 protocol-compatible non-correlated pairs (NCPs) by pairing the source transaction with distractor transactions on Solana. This yields 212,460 NCPs and 219,542 candidate pairs in total. The Raw Data column reports the number of records obtained during data acquisition, while the per-sourcechain CP/NCP columns report the verified associations and their corresponding constructed distractors.
A. Dataset Construction We collect and verify real-world Solana-bound cross-chain transfers from four EVM-compatible source chains, including Ethereum, Arbitrum, Base, and Polygon PoS, across four representative bridges covering all four transaction modes. Across the main and generalization data-collection rounds, our acquisition pipelines retrieved 38,317 bridge records and retained 7,082 verified source–target pairs after deduplication, dual-chain verification, and bridge-specific consistency checks. • Wormhole: We use Wormhole WTT as the representative MRT product and collect 5,977 transfer records from WormholeScan. After cross-file deduplication and dualchain RPC verification, 1,625 valid source–target pairs are retained, including 1,082 from Ethereum, 68 from Arbitrum, 279 from Base, and 196 from Polygon PoS. • Allbridge: We use Allbridge Core as the representative PST product and collect 1,480 transfer records from the Allbridge Core Explorer backend. RPC verification, transaction decoding, deduplication, and unstable-target filtering yield 1,341 valid pairs, including 795 from Ethereum and 182 from each of Arbitrum, Base, and Polygon PoS. • deBridge: We use deBridge DLN as the representative SFT product and collect 1,600 fulfilled orders from the official Stats API. RPC-based verification of source
B. Experimental Settings 1) Environments: All experiments are conducted on a laptop running Windows 11 64-bit, equipped with an AMD Ryzen 9 5900HX 8-Core CPU, an NVIDIA GeForce RTX 3060 Laptop GPU with 6 GB memory, and 16 GB RAM. The experimental programs are implemented in Python 3.13.10. 2) Methods in Comparison: To comprehensively evaluate the performance of SolTracer, we employ six typical methods for comparison, which can be categorized into two categorizes. Heuristic-based methods: • Attribute Matching (AttrMatch) [8] scores candidate transaction pairs based on time, amount, and asset consistency, accepting associations above a tuned threshold. • Entity-Aware Matching (EntityMatch) [8] extends the AttrMatch by incorporating recipient and counterparty consistency into the threshold-based association decision. • Multi-Constraint Matching (MultiMatch) [11] establishes a deterministic rule-based framework over reconstructed events, associating cross-chain transactions only when a candidate uniquely satisfies strict account, timing, amount, and token constraints. Learning-based methods: • CONNECTOR [5] extracts bridge-contract execution features to identify deposit events on the source chain and
8
2Pg Rg Pg + R g (7) where TPg , FPg , and FNg denote correctly rejected targetabsent groups, falsely rejected target-present groups, and unrejected target-absent groups, respectively. 4) Validation. A candidate group is defined as TargetPresent (TP) when it contains a verified Solana-side target, and as Target-Absent (TA) when the verified target is removed through controlled masking. We vary the TP/TA ratio to evaluate both closed-world association and openworld association under different degrees of class imbalance. All datasets are partitioned at the candidate-group level into mutually exclusive training, validation, and test sets. The closed- and open-world experiments use Ethereum-to-Solana data, whereas cross-source-chain generalization uses Ethereum for training and calibration and Arbitrum, Base, and Polygon PoS for evaluation. 5) Implementation Details. During candidate ranking, S OLT RACER employs a random forest over 14 semantic features, with 300 trees, balanced class weights, and a minimum leaf size of two. The candidate-set rejector uses ranking and semantic-consistency evidence, while excluding candidate count and minimum time distance to prevent structural leakage. To reduce the impact of randomness,the main closedworld, open-world, and generalization experiments are each repeated with five fixed seeds (7, 11, 19, 23, and 42), and the mean results are reported. Pg =
TPg , TPg + FPg
Rg =
TPg , TPg + FNg
F 1g =
C. Sensitivity Analysis 1) Candidate-pair threshold τp . The threshold τp determines whether an individual cross-chain association is accepted in
(a) Candidate-pair acceptance Precision
Recall
0.4
0.6
F1
1.0
Rate
0.8 0.6 0.4 0.2 0.0 0.0
0.2
0.8
Candidate-pair threshold
0.94
1.0
(b) Candidate-set rejection Pg acceptance Rg F1gthresholds τp ∈ [0, 1]. Fig. 5. Sensitivity of candidate-pair across The star and vertical dashed line indicate the optimal threshold (τp = 0.94) 1.0 maximizing F1. 0.8
Rate
Rate
0.6 closed-world scenarios. To find the optimal operating point without we perform a grid sweep of τp from 0 0.4 data leakage, (a) Candidate-pair acceptance to 1 with a step size ofPrecision 0.01 over the 12,400F1validation pairs Recall 1.0 (3710.2 positive and 12,029 negative) to maximize the candidatelevel0.0F1-score. As shown in Fig. 5(a), low thresholds retain 0.8 0.2 but admit 0.4 substantial 0.6 0.8 distractors, 1.0 nearly 0.0 all true targets negative 0.227 Candidate-set threshold leading 0.6 to low precision. As τp increases, precision improves monotonically while recall remains stable above 0.92 until τp =0.40.98. At τp = 0.94, candidate F1 peaks at 97.25%. Notably, 0.2the F1 curve exhibits a stable plateau across [90%, 98%], demonstrating SolTracer’s robustness against threshold variations0.0over an isolated peak.0.4 0.0 0.2 0.6 0.8 1.0 0.94
Candidate-pair threshold
(b) Candidate-set rejection Pg
Rg
F1g
1.0 0.8
Rate
links them to corresponding target withdrawals using onchain execution evidence. • ABCTRACER [6] combines event mining and namedentity recognition for explicit cross-chain cue extraction with an information-retrieval ranking model for implicit cue matching. • ConneX [7] leverages large language models to extract semantic key-value pairs from transaction logs and applies programmatic value-consistency checks to identify valid target evidence. To adapt these methods to the heterogeneous EVM-toSolana setting, we replace their EVM-specific input fields with a unified semantic-event representation.AttrMatch, EntityMatch, and MultiMatch apply their original scoring or constraint rules to the corresponding time, amount, asset, and participant fields. For CONNECTOR, ABCTRACER, and ConneX, EVM-specific log inputs are replaced with the corresponding execution evidence or semantic key–value records, while their original association mechanisms are retained. 3) Metric: We evaluate performance using precision (P ), recall (R), and F1-score (F 1) as they are standard in this research field [14], [24], [25]. In open-world scenarios with selective rejection [26], group-level metrics (Pg , Rg , F 1g ) quantify the capability to abstain when no valid target exists:
0.6 0.4 0.2 0.0 0.0
0.2 0.227
0.4
0.6
0.8
1.0
Candidate-set threshold
Fig. 6. Sensitivity of candidate-set rejection across thresholds τr ∈ [0, 1]. The star and vertical dashed line indicate the optimal operating point (τr = 0.227) maximizing group-level F1.
2) Candidate-set rejection threshold τr . The threshold τr dictates whether a ranked candidate pool provides sufficient evidence to return any association in open-world scenarios. We generate out-of-fold support probabilities via 5-fold stratified cross-validation on the 400 validation groups, selecting the threshold τr that maximizes the F 1g . As shown in Fig. 6(b), the optimal boundary is identified at τr = 0.227, achieving Pg = 89.74%, Rg = 87.50%, and F 1g = 88.61% by correctly rejecting 35 of the 40 TA validation groups while incorrectly rejecting only 4 of the 360 TP groups. Beyond this operating point, precision degrades sharply because the model aggressively rejects valid TP groups despite higher TA
9
TABLE III C LOSED - WORLD ASSOCIATION PERFORMANCE (%) ACROSS DIFFERENT TRANSACTION MODES . MRT
Method P
R
PST F1
P
R
SFT F1
P
R
P
R
AttrMatch 0.00 EntityMatch 0.00 MultiMatch 100.00 CONNECTOR 0.00 ABCTRACER 86.30 ConneX 88.76
0.00 0.00 97.83 100.00 98.90 0.00 0.00 97.83 100.00 98.90 93.33 96.55 0.00 0.00 0.00 0.00 0.00 96.77 100.00 98.36 86.30 86.30 85.19 85.19 85.19 87.78 88.27 97.78 97.78 97.78
85.05 79.82 0.00 81.82 70.74 84.71
82.73 82.73 0.00 65.45 57.88 65.45
83.87 80.91 81.25 78.07 0.00 100.00 72.73 75.42 63.67 92.96 73.85 84.44
SolTracer
96.67
93.33 96.00
99.10
100.00
99.55
100.00
98.31
98.82
recall. These two complementary curves confirm that pair-level filtering and set-level abstention govern distinct error modes and achieve stable performance when calibrated independently. D. Evaluation in Closed-World Scenario The closed-world settings evaluates candidate discrimination when the ground-truth target is guaranteed to exist within the observation pool across diverse bridge architectures. We partition 2,340 positive groups into 1,620 training, 360 validation, and 360 held-out test groups with 90 groups per transaction mode. Table III reports candidate-level F1-scores across all four individual transaction modes along with overall performance on the complete 360-group test set. We have the following main observations. 1) SolTracer achieves the best overall association performance across heterogeneous transaction modes. SolTracer attains an overall F1 of 98.13%, outperforming the strongest baseline, ConneX, by 12.30 percentage points, while maintaining both high precision (99.46%) and recall (96.84%). In contrast, existing methods exhibit strong mode dependence: strict constraints cause MultiMatch to miss valid targets, whereas attribute- and execution-based methods fail when their matching cues are not preserved across mechanisms. This demonstrates that mode-guided semantic reconstruction provides more consistent association evidence across heterogeneous bridge transactions. 2) SolTracer shows greater advantages under stronger semantic transformations. SolTracer achieves the highest F1 on MRT, SFT, and BMT, reaching 98.31%, 99.55%, and 98.31%, respectively, with the largest gain of 15.68 percentage points on SFT. This advantage stems from recovering mechanismspecific evidence such as redemption roles, solver fulfillment, and burn–mint semantics. On PST, AttrMatch and EntityMatch reach 98.90%, slightly above SolTracer’s 96.00%, because time, asset, and amount consistency remains sufficiently discriminative in this mode. E. Evaluation in Open-World Scenario The open-world protocol relaxes the target-availability assumption to evaluate whether a method can selectively abstain when valid target evidence is unavailable [26]. We use the same 2,600 Ethereum-to-Solana groups, partitioned into 1,800 training, 400 validation, and 400 test groups, and construct
Overall
BMT F1
98.89 98.89 78.89 98.89 92.96 84.44
100.00 96.67
F1
P
R
F1
89.00 87.38 87.25 84.38 88.20 100.00 85.58 83.95 92.96 83.80 84.44 88.98
71.05 71.05 40.79 66.05 79.39 82.89
78.37 77.14 57.94 73.93 81.53 85.83
99.46
96.84
98.13
98.31
TABLE IV OPEN - WORLD ASSOCIATION PERFORMANCE (%) ACROSS DIFFERENT METHODS .
10%
Method
30%
50%
F1
F 1g
F1
F 1g
F1
F 1g
AttrMatch EntityMatch MultiMatch CONNECTOR ABCTRACER ConneX
78.03 76.70 57.94 72.75 77.35 83.33
44.05 44.05 28.07 38.46 – 56.25
76.36 74.73 57.42 70.65 67.81 77.92
72.67 71.81 60.00 68.18 – 65.22
73.71 71.60 55.70 67.31 55.07 69.25
84.60 83.80 77.37 81.28 – 63.76
SolTracer
96.50 94.87 95.22 95.69 93.87 97.19
three open-world settings with TA ratios of 10%, 30%, and 50%. For each setting, the corresponding proportion of groups is designated as Target-Absent by removing the verified target while retaining protocol-compatible distractors. Table IV reports F 1 and F 1g under the three TA ratios. We have the following observations. 1) Increasing target absence exposes the limitation of pairlevel association. As the TA ratio increases, the candidate-level performance of all baseline methods generally deteriorates. For example, ConneX decreases from 83.33% to 69.25% in F 1, while ABCTRACER drops more sharply from 77.35% to 55.07%. This degradation indicates that methods designed primarily to identify the best candidate become increasingly vulnerable when valid targets are absent from a larger fraction of candidate sets. Although several heuristic methods obtain higher F 1g at larger TA ratios, their candidate-level F 1 continues to decline, showing that stronger rejection under frequent target absence does not necessarily imply reliable association of target-present groups. 2) Candidate-set selective decision remains robust across different TA ratios. SolTracer consistently achieves the highest candidate-level F 1, decreasing only moderately from 96.50% at 10% TA to 93.87% at 50% TA. In contrast, its rejection F 1g remains above 94% across all settings and increases from 94.87% to 97.19% as target absence becomes more prevalent. Moreover, its candidate-level advantage over the strongest baseline widens from 13.17 percentage points at 10% TA to 20.16 percentage points at 50% TA. These results show that separating within-set ranking from candidate-set-
10
TABLE V C ROSS - SOURCE - CHAIN GENERALIZATION PERFORMANCE (%) ACROSS DIFFERENT METHODS . Arbitrum-to-Solana
Method
F1
Base-to-Solana
P
R
F 1g
AttrMatch EntityMatch MultiMatch CONNECTOR ABCTRACER ConneX
81.50 74.91 75.00 68.66 37.50 77.50
94.44 100.00 72.22 100.00 41.67 86.11
83.79 62.50 83.24 50.00 73.53 71.21 79.66 50.00 39.47 0.00 81.58 50.00
SolTracer
100.00
93.89
96.06
PolygonPoS-to-Solana
P
R
F1
F 1g
P
R
83.41 79.01 75.00 77.31 38.33 79.44
86.11 100.00 75.00 100.00 42.59 83.33
82.97 88.07 75.00 87.00 40.35 81.29
82.14 100.00 79.55 100.00 0.00 50.00
86.70 78.27 75.00 75.77 45.83 90.00
100.00 100.00 75.00 100.00 50.93 97.22
89.76 100.00
97.78
98.79
94.17
100.00
97.22
level abstention allows SolTracer to preserve accurate target association while adapting to substantial variation in target availability, making it more reliable under the imbalanced conditions encountered in real-world cross-chain tracing. F. Evaluation on Generalization To evaluate cross-source-chain generalization, we calibrate all methods on Ethereum-to-Solana transfers and directly apply the frozen configurations to Arbitrum, Base, and Polygon PoS. Table V reports candidate association and candidate-set rejection performance on the three unseen source chains. We have the following observations. 1) SolTracer achieves the strongest overall cross-sourcechain generalization. SolTracer obtains an overall candidate F1 of 97.79% and rejection F 1g of 91.87%, exceeding the strongest baselines by 11.33 and 10.32 percentage points, respectively. In contrast, heuristic methods remain dependent on predefined attribute assumptions, while learned baselines degrade when source-chain-specific execution patterns shift. The results indicate that protocol- and mode-guided semantic evidence provides a more transferable representation across EVM source chains. 2) SolTracer remains consistently effective across all unseen source chains. Its candidate F1 reaches 96.06%, 98.79%, and 98.53% on Arbitrum, Base, and Polygon PoS, outperforming the strongest baseline by 12.27, 10.72, and 5.11 percentage points, respectively. Although ConneX becomes more competitive on Polygon PoS, other baselines show larger variations across source chains. SolTracer’s consistently high association and rejection performance suggests that semantic reconstruction reduces sensitivity to source-chain distribution shifts. G. Ablation Study In this subsection, we systematically evaluate the contribution of each core module in SolTracer, including the protocol identification module, the semantic event reconstruction module, the candidate classifier, and the candidate-set selective decision mechanism. All variants are evaluated on the standardized test benchmark containing 360 target-present and 40 target-absent groups. Table VI presents the association and rejection performance across different configurations. 1) Protocol Identification. Without protocol-guided filtering, the candidate matching F1 drops sharply by 20.93%, and the
F1
F 1g
Overall P
R
F1
F 1g
92.61 100.00 86.93 75.00 75.00 79.55 85.61 75.00 48.25 0.00 93.42 25.00
83.87 77.40 75.00 73.91 40.55 82.31
93.52 100.00 74.07 100.00 45.06 88.89
86.46 86.08 74.51 84.09 42.69 85.43
81.55 75.00 76.77 75.00 0.00 41.67
98.53
100.00
96.30
97.79 91.87
91.67
TABLE VI A BLATION RESULTS ON INDIVIDUAL S OLT RACER MODULES (%). F1
F 1g
96.50 75.57 ↓20.93
94.87 37.86 ↓57.01
96.90 96.37 ↓0.53
98.73 96.10 ↓2.63
Classifier
Random Forest∗ 96.50 w/ Logistic Regression 77.98 ↓18.52 w/ XGBoost 96.50
94.87 62.92 ↓31.95 91.89 ↓2.98
Association Decision
Selective Decision∗ w/o Selective Decision
Category
Configuration
Protocol Identification
Protocol-Guided∗ w/o Protocol-Guided
Mode-Guided∗ Event Reconstruction w/ Generic Repr.
∗
96.50 92.05 ↓4.45
94.87 –
Default setting. Red values (↓) denote performance degradation from the default.
rejection score F 1g collapses from 94.87% to 37.86%. This severe performance degradation occurs because generic matching relies strictly on raw attribute consistency, which fails under cross-chain conversions and causes supported targets to be incorrectly filtered out. 2) Event Reconstruction. Replacing the mode-guided reconstruction with a generic representation reduces the candidate F1 to 96.37% and causes a 2.63% drop in set-level rejection F 1g . Reconstructing mode-specific account roles and inner invocations provides indispensable semantic cues for distinguishing target candidates and assessing candidate-set support. 3) Classifier. Linear models like Logistic Regression achieve an F1 of only 77.98% and an F 1g of 62.92%, highlighting the need for nonlinear modeling across heterogeneous feature interactions. While XGBoost achieves a comparable candidate F1 of 96.50%, its set rejection F 1g degrades by 2.98%, confirming that Random Forest delivers the most balanced rejection capability. 4) Association Decision. Removing the candidate-set reject option and forcing the model to return the top candidate decreases candidate F1 from 96.50% to 92.05%, while completely losing the ability to identify target-absent groups. This confirms that selective abstention is crucial to prevent forced false-positive attributions in open-world tracing. VII. E MPIRICAL I NSIGHTS ON S OLANA C ROSS -C HAIN T RANSACTIONS In this section, we analyze the cross-chain transactions associated by S OLT RACER to uncover key operational and security
11
characteristics of the Solana bridge ecosystem. Specifically, we investigate count–value divergence, cross-asset shifts, target observability gaps, and mechanism-dependent association reliability.
A. Difference Between Transaction Count and Value To examine whether transaction frequency reflects the economic concentration of Solana-bound bridge activity, we compare the record share against the reported USD-volume share across the four transaction modes. We restrict this analysis to Ethereum-to-Solana transfers collected over a 28-day window from March 25 to April 22, 2026 UTC, spanning 16,790 records and $178.53 million in source-side volume. Fig. 7 illustrates the distribution.
B. Cross-Asset Settlement Patterns To examine how intermediate token conversions impact fund lineage across heterogeneous chains, we analyze the distribution shift between source-side deposit assets and Solana-side settlement assets across all indexed transfers. Specifically, we quantify the token breakdown across both chains and measure the degree of asset transformation induced by automated DEX routing and solver fulfillment. Fig. 8 illustrates the compositional divergence across the 47,117 collected crosschain records. (a) Source assets 9.1%
36.1%
90.9%
17.0% 0.8% 65.9%
USDC
SOL
USDT
Other
Unknown
16.3%
(b) Reported USD-volume share MRT PST SFT BMT
9.1% 6.5% 47.2%
(a) Record share MRT PST SFT BMT
(b) Solana settlement assets
33.3% 0.1% 15.5% 51.0%
0
20 40 60 Share of four-mode total (%)
Fig. 7. Record and reported USD-volume shares across the four Ethereumto-Solana transaction modes.
As shown in Fig. 7, SFT accounts for 65.86% of total transactions but only 15.53% of volume. Its intent-based solver model predominantly handles high-frequency, pricesensitive DEX swaps and cross-chain arbitrage of relatively small amounts [19], [27]. Conversely, BMT exhibits the opposite pattern, contributing only 16.28% of transactions while commanding 51.03% of total volume. Its native burnand-mint mechanism serves large-scale capital deployments and liquidity rebalancing by market makers and institutional entities [28]. Similarly, MRT shows a higher volume share than transaction share, reflecting direct high-value asset transfers. PST accounts for minimal activity across both metrics on the evaluated route. Overall, transaction frequency does not directly reflect economic exposure: frequent solver orders process fragmented retail volume, whereas less frequent burn-and-mint operations concentrate substantial liquidity. Finding 1. Solana-bound bridge activity exhibits a stark count–value divergence. SFT generates the highest transaction count, while BMT and MRT account for the vast majority of transferred value. Monitoring frameworks relying solely on transaction frequency fail to capture high-value systemic capital flows.
Fig. 8. Source-side and Solana-side asset composition in the indexed dataset. Unknown indicates missing target-side token symbols.
As depicted in the distributions, USDC dominates sourcechain deposits at 90.90%, but its representation plunges to 47.24% upon Solana settlement. Concurrently, native SOL comprises 36.13% of settlement assets, while unspecified tokens, alternative SPL assets, and USDT account for 9.13%, 6.51%, and 0.98%, respectively. Overall, non-USDC assets surge from 9.10% on the source chain to 52.76% on Solana, demonstrating that cross-asset settlement is the prevailing pattern rather than an exception. While cross-asset swaps offer flexibility for retail users, they inherently disrupt the semantic continuity of cross-chain fund flows. By altering token contracts, payout values, and decimal precisions within solver executions, cross-asset routes allow illicit actors to mimic legitimate DEX swaps and bypass static AML amount-matching rules. Tracing frameworks that enforce raw asset or balance equality inevitably fail across such intentbased mechanisms. Finding 2. Cross-chain settlements frequently transform asset composition, with non-USDC shares surging from 9.10% to 52.76% on Solana. Because automated crossasset swaps alter fundamental transfer attributes, reliable tracing cannot assume source–target asset equality. C. Separation Between Settlement and Visibility To assess whether missing target joins in explorer records stem from actual cross-chain execution failures or target observability gaps on Solana, we investigate the resolution status of all unlinked source-side transactions. Specifically, we replay these records through S OLT RACER against bounded Solana candidate pools and mode-specific semantic evidence to differentiate pre-cutoff settlements, candidate ambiguity, and genuinely unredeemed transfers. Fig. 9 presents the overall
12
proportion of source-only records and the empirical breakdown of recovered targets. (a) Full census Original target join 57.12%
0
20
40 60 80 (b) Diagnostic breakdown
10.9%
0
Target-unconfirmed 42.88%
73.5%
20
100
D. Mode-Dependent Association Reliability To understand how disparate bridge architectures influence cross-chain tracing reliability under open-world target uncertainty, we examine the discriminative strength of candidateset evidence across the four transaction modes. Specifically, we evaluate the error distributions and candidate separation profiles across time, amount, asset, recipient, and role cues under both target-present and target-absent settings. Fig. 10 summarizes the mechanism-specific evidence retention patterns for candidate-set decisions. (a) MRT Asset Amount
14.7%
40 60 Share (%)
80
100
Recovered before cutoff (2,199)
Circle CCTP unresolved (14,848)
Recovered after cutoff (2)
Wormhole WTT unresolved (2,969)
Role
Among the 47,117 indexed bridge records, 20,202 transfers (42.88%) contain only an origin deposit without an explicit target-side link. Our replay analysis resolves these unlinked transfers into three distinct categories: 1) Settled but Unlinked Transfers. S OLT RACER recovers 2,201 unique target transactions from the source-only subset. Crucially, 2,199 of these targets (1,493 Circle CCTP and 706 Wormhole WTT transactions) had settled successfully onchain prior to the collection cutoff, while only two settled afterward. This confirms that missing links primarily reflect target-side indexing omissions rather than long settlement delays. Because Solana scatters execution state across inner CPIs and balance deltas without emitting standard top-level receipt logs, general-purpose explorers fail to capture and associate these completed payouts. 2) Ambiguous Associations. Another 184 Circle CCTP transfers match multiple concurrent mint operations satisfying identical temporal, recipient, and amount constraints. In such cases, observable target evidence exists but cannot support a unique attribution, highlighting the necessity of set-level selective rejection to avoid false linkages. 3) Unresolved Transfers. The remaining transfers (14,848 Circle CCTP and 2,969 Wormhole WTT records) yield no valid match within the observation window. These records correspond to unsupported custom routes, long-tail finality delays, or genuinely unexecuted transactions. Rather than forcing false associations, S OLT RACER abstains from linking them. Finding 3. On-chain settlement on Solana is decoupled from receipt-level observability. Over 10.8% of unindexed records had settled successfully on-chain prior to the collection cutoff, demonstrating that standard explorers miss valid transactions due to CPI-fragmented execution traces.
34
5 Time
12
Role
34
5 Time
Recipient Separation
Recipient Separation
(c) SFT Asset Amount
(d) BMT Asset Amount
Ambiguous Circle CCTP (184)
Fig. 9. Distribution of source-only records and the empirical breakdown resolved by S OLT RACER.
12
(b) PST Asset Amount
Role
12
34
5 Time
Recipient Separation
Role
12
34
5 Time
Recipient Separation
Larger radii indicate stronger retained evidence for group-level decisions.
Fig. 10. Discriminative evidence profiles across the four Solana cross-chain transaction modes.
The empirical evidence profiles explain the systematic divergence in association and rejection performance across modes: MRT preserves direct recipient and redemption-role cues once inner CPI invocations to the SPL Token program are resolved. PST introduces amount deviations through dynamic pool slippage and liquidity fees, while shared pool contracts generate concurrent payouts with overlapping value ranges. SFT exhibits the weakest direct linkage because solver fulfillment decouples funding accounts and permits cross-asset conversions. BMT maintains clean recipient and amount semantics, yet its off-chain attestation verification makes candidate separation vulnerable to concurrent identical-value mint batches. Finding 4. Association and rejection reliability depends heavily on the underlying bridge mechanism. Because evidence retention profiles differ structurally across MRT, PST, SFT, and BMT, reliable open-world tracing requires mode-specific feature modeling and calibrated abstention. VIII. C ONCLUSION This work is the first to systematically explore cross-chain transaction tracing on Solana across heterogeneous ledgers. We analyzed the unique execution models and transaction record designs between EVM and Solana, identifying four fundamental Solana-bound transaction modes based on their settlement mechanisms, namely MRT, PST, SFT, and BMT.
13
Subsequently, we proposed SolTracer, a cross-chain tracing method based on candidate-set selective decision, which effectively reconstructs semantic bridge events and reliably associates target transactions.Extensive experiments demonstrate that SolTracer outperforms state-of-the-art methods across closed-world, open-world, and cross-source-chain generalization scenarios. In the open-world scenario, SolTracer improves the F1 score by up to 20.16% over the strongest baseline. We then conducted an empirical analysis on real-world cross-chain transfers, exploring the count-value divergence, cross-asset settlement shifts, target-observability gaps, and mechanismdependent association reliability. In the future, we will extend method identification and selective decision-making to evolving routes and multi-hop cross-chain settlements. R EFERENCES [1] CoinMarketCap, “Cryptocurrency Market Capitalizations,” https:// coinmarketcap.com/, 2026, [Accessed: Aug. 13, 2026]. [2] Scam Sniffer, “Solana drainers,” [Online]. Available: https://drops.scamsniffer.io/?p=850, 2024, accessed: Jun. 4, 2026. [3] J. Nelson, “Hackers steal over $4 million in fake airdrops and other scams on Solana,” [Online]. Available: https://decrypt.co/212875/hackers-steal-over-4-million-fake-airdropsother-scams-solana, 2024, accessed: Jun. 4, 2026. [4] SlowMist, “2024 blockchain security and AML annual report,” [Online]. Available: https://www.slowmist.com/report/2024-Blockchain-Securityand-AML-Annual-Report [5] D. Lin, J. Wu, Y. Su, Z. Zheng, Y. Nan, Q. Zhang, B. Song, and Z. Zheng, “Connector: Enhancing the traceability of decentralized bridge applications via automatic cross-chain transaction association,” IEEE Transactions on Information Forensics and Security, vol. 20, pp. 7588– 7601, 2025. [6] D. Lin, Z. Zheng, J. Wu, J. Yang, K. Lin, H. Xiao, B. Song, and Z. Zheng, “Track and trace: Automatically uncovering cross-chain transactions in the multi-blockchain ecosystems,” IEEE Transactions on Services Computing, vol. 18, no. 6, pp. 4291–4303, 2025. [7] H. Liang, Y. Duan, X. Su, X. Li, Y. Liu, Y. Tian, F. Xu, and S. Zhong, “Connex: Automatically resolving transaction opacity of cross-chain bridges for security analysis,” 2025. [8] H. Yousaf, G. Kappos, and S. Meiklejohn, “Tracing transactions across cryptocurrency ledgers,” in Proc. 28th USENIX Security Symposium, 2019, pp. 837–850. [9] Z. Zhang, J. Yin, B. Hu, T. Gao, W. Li, Q. Wu, and J. Liu, “Cltracer: A cross-ledger tracing framework based on address relationships,” Computers & Security, vol. 113, p. 102558, 2022. [10] Y. Hu, Y. Sun, L. Wu, Y. Zhou, and R. Chang, “Towards understanding and analyzing instant cryptocurrency exchanges,” Proceedings of the ACM on Measurement and Analysis of Computing Systems, vol. 8, no. 3, pp. 1–24, 2024. [11] T. Yan, C. Huang, and C. J. Tessone, “Tracing cross-chain transactions between evm-based blockchains: An analysis of ethereum-polygon bridges,” arXiv preprint arXiv:2504.15449, 2025. [12] Y. Cao, M. Zheng, L. W. Cong, S. Li, and X. Wang, “The price of interoperability: Exploring cross-chain bridges and their economic consequences,” Proceedings of the ACM on Measurement and Analysis of Computing Systems, vol. 10, no. 2, pp. 1–29, 2026. [13] M. Zhang, X. Zhang, Y. Zhang, and Z. Lin, “Cross-chain bridges: Attack taxonomy, defenses, and open problems,” in Proc. International Symposium on Research in Attacks, Intrusions and Defenses, 2024, pp. 298–316. [14] Z. Li, Z. Jiang, M. Fang, J. Chen, Z. Wu, J. Wu, L. Zhang, and Z. Zheng, “Solphishhunter: Toward detecting and understanding phishing on solana,” IEEE Transactions on Information Forensics and Security, vol. 21, pp. 757–771, 2025. [15] Wormhole Foundation, “Wormholescan API: Cross-Chain Operations Endpoint,” https://api.wormholescan.io/api/v1/operations, 2026, [Online; accessed 23-April-2026]. [16] deBridge, “deBridge DLN API: Orders Filtered List Endpoint,” https:// dln-api.debridge.finance/api/Orders/filteredList, 2026, [Online; accessed 16-May-2026].
[17] Allbridge, “Allbridge Core Explorer,” https://core.allbridge.io/explorer, 2026, [Online; accessed 18-May-2026]. [18] Stargate, “Architecture,” Stargate Documentation. [Online]. Available: https://docs.stargate.finance/introduction/architecture, accessed: Aug. 10, 2026. [19] deBridge, “DLN protocol overview,” deBridge Documentation. [Online]. Available: https://docs.debridge.com/dln-details/overview/protocoloverview, accessed: Jul. 31, 2026. [20] Mayan, “Swift,” Mayan Documentation. [Online]. Available: https://docs.mayan.finance/architecture/swift, accessed: Aug. 10, 2026. [21] Across Protocol, “Intent lifecycle in Across,” Across Documentation. [Online]. Available: https://docs.across.to/guides/concepts/intentlifecycle, accessed: Aug. 10, 2026. [22] Circle Internet Financial Ltd., “Circle Iris API: Cross-Chain Transfer Protocol (CCTP) Message Attestation Endpoint,” https://iris-api.circle.com/v2/messages/\{sourceDomainId\}? transactionHash=\{sourceTxHash\}, 2026, [Online; accessed 2May-2026]. [23] LayerZero Labs, “Solana OFT,” LayerZero Documentation. [Online]. Available: https://docs.layerzero.network/v2/developers/solana/oft/overview, accessed: Aug. 10, 2026. [24] H. Du, M. Shen, Y. Liu, Z. Che, J. Wu, W. Wang, and L. Zhu, “Finegrained and class-incremental malicious account detection in ethereum via dynamic graph learning,” IEEE Transactions on Information Forensics and Security, 2025. [25] J. Wu, K. Lin, D. Lin, B. Zhang, Z. Wu, and J. Su, “Safeguarding blockchain ecosystem: Understanding and detecting attack transactions on cross-chain bridges,” in Proc. ACM Web Conference, 2025, pp. 4902– 4912. [26] Y. Geifman and R. El-Yaniv, “SelectiveNet: A deep neural network with an integrated reject option,” in Proc. 36th International Conference on Machine Learning, ser. Proceedings of Machine Learning Research, vol. 97, 2019, pp. 2151–2159. [27] deBridge, “Swaps: Integrate cross-chain and same-chain swaps in your app,” deBridge Documentation. [Online]. Available: https://docs.debridge.com/home/use-cases/swaps, accessed: Jul. 31, 2026. [28] Circle, “Cross-chain transfer protocol V1,” Circle Documentation. [Online]. Available: https://developers.circle.com/cctp/v1, accessed: Jul. 31, 2026.