A forensic report on Aurum’s NEYRO product alleges that the project was marketed as a non-custodial AI trading bot but actually routed user deposits into a pool controlled by the operator. The report says funds were then moved out through wallets and exchange services, leaving users without a practical withdrawal path.
The underlying risk is not a sophisticated exploit in code execution but a custody failure hidden behind product claims. When a contract gives operators unilateral control over assets, users are exposed to a drain even if the interface suggests otherwise.
To defend against this class of loss, users and auditors should verify whether a contract actually exposes withdrawal rights to depositors. Projects should publish audited source code, make control flows explicit, and avoid marketing language that implies user ownership when operator custody exists.
Security teams should also watch for fund-flow patterns that indicate laundering after deposits, especially repeated transfers to fresh addresses or swap services. Those patterns often matter more than the front-end story when assessing whether a system is truly non-custodial.