Cover image

Same Chain, Different Signal: Why Solana Rug-Pull Models Do Not Travel Cleanly

TL;DR for operators Five minutes of on-chain trading activity contain enough signal to support one-hour rug-pull screening on Solana, but the signal is not reliably portable across venues. A model that performs reasonably on PumpFun can lose much of its separation when moved to Raydium, and vice versa. Training on both venues helps—especially for XGBoost and Random Forest—but does not remove the platform effect. ...

September 23, 2026 · 6 min · Zelina
Cover image

Decision Rights, Not More Layers: What an Auditable Fraud Pipeline Actually Earns

TL;DR for operators A fraud classifier has already scored a transaction. The next operational choice is whether extra context—relationship patterns, anomaly signals, explanations, or an LLM investigator—should merely inform the case or be allowed to change the decision. In Rahil Sharma’s evaluation, the answer is component-specific.1 The bounded LLM investigator was correct on 39 of 60 deliberately balanced difficult cases, versus 43 of 60 for simply applying a 0.5 threshold to the classifier: 65.0% versus 71.7%. The agent changed eight classifier decisions. Two changes fixed mistakes; six replaced correct decisions with incorrect ones. ...

August 24, 2026 · 7 min · Zelina
Cover image

The Network Failed. The Fraud Model Saw Fraud.

TL;DR for operators A transaction fails repeatedly on a weak network. To a fraud model, the retries, interruptions, and irregular timing can resemble suspicious activity. Yet the apparent risk signal may describe infrastructure quality rather than fraudulent intent. Better calibration or a higher confidence threshold can identify uncertain cases, but neither explains the source of uncertainty nor determines who should resolve it. ...

August 5, 2026 · 8 min · Zelina
Cover image

When Riders Become Nodes: Mapping Fraud in Ride-Hailing with Graph Neural Networks

A ride can look perfectly normal. The driver accepts a request, reaches the pickup point, and ends the trip shortly afterward. Nothing in that single transaction necessarily screams fraud. But place it beside the driver’s repeated early completions, the passengers who frequently disappear from the platform after pickup, and the same locations where similar cancellations occur, and the pattern changes. ...

January 4, 2026 · 17 min · Zelina
Cover image

Graph Crimes of the Temporal Kind: How LoReTTA Quietly Breaks Time

A fraud model does not only learn from transactions. It learns from sequence. Who interacted with whom. When. How often. After what previous event. Before which next event. In temporal graph systems, the order is not metadata. It is the thing being modelled. That is why LoReTTA is an uncomfortable paper.1 It does not argue that Temporal Graph Neural Networks can be broken only by a powerful adversary with model access, expensive surrogate training, and a theatrical pile of fake edges. It argues something more operationally annoying: a continuous-time graph can be poisoned by removing influential interactions and replacing them with plausible ones. The resulting history still looks enough like history. The model quietly learns the wrong temporal structure. Very civilised, as crimes go. ...

November 16, 2025 · 16 min · Zelina
Cover image

Fraud, Trimmed and Tagged: How Dual-Granularity Prompts Sharpen LLMs for Graph Detection

TL;DR for operators Fraud teams already know the problem: the suspicious review, shop, seller, or account is rarely suspicious in isolation. The useful evidence is scattered across neighbours — same user, same product, same rating pattern, same time window, same commercial ecosystem. The less useful evidence is also scattered there. At scale, that second pile is larger. How inconvenient. ...

July 30, 2025 · 15 min · Zelina