Drift exploiter moves $44M through Tornado Cash after months

By: rootdata|2026/07/24 08:20:36

A wallet tied to the $285 million Drift Protocol exploit moved 23,095.1 Ether, worth about $44.4 million, into Tornado Cash after roughly three months of inactivity.

Summary

  • Drift's exploiter deposited 23,095 ETH into Tornado Cash after remaining inactive for three months.
  • ZachXBT declined further tracking, citing resources required to monitor and freeze a nine-figure DPRK theft.
  • Drift previously announced a recovery bounty program with Arkham and Bybit, contrary to online claims.

The same address sent 0.85 ETH to wallets labeled as Bybit deposit addresses, according to Etherscan records and monitoring attributed to PeckShield.

Transfers began on July 23 and continued into July 24, on-chain records show. Researcher JL, known as 0xJaelle, flagged the movement and tagged ZachXBT. The investigator replied that he did not plan to keep following the funds without institutional support.

The drift exploiter moving funds finally.

Onchain Lens first reported that the attacker had resumed activity and was sending 100 ETH batches into the mixer several times per minute. The wallet had remained largely inactive since the April attack.

Tornado Cash pools deposits and permits later withdrawals through different addresses. That can weaken the direct public link between sending and receiving wallets. Investigators may still use timing, transaction patterns and exchange activity, but the process requires more data and staff.

The movement covers only part of the original theft. Drift's April recovery update valued stolen assets at $295.7 million across JLP, USDC, Bitcoin-linked tokens, SOL, WETH and other assets. The protocol said much of the converted value remained across four flagged Ethereum wallets.

ZachXBT wrote, "Sorry I currently do not have any plans to track these funds further." He said monitoring a nine-figure North Korea-linked exploit and working toward possible freezes would require resources beyond one independent investigator.

He described the task as "difficult for a team and not feasible for a single person." ZachXBT also said Drift was not a donor or client. His response on X drew attention to the cost of investigations that continue for months.

The comments do not show that no organization is watching the wallets. Drift has said it works with law enforcement, Mandiant and blockchain intelligence firms. Etherscan continues to label the address, while exchanges can review deposits connected to flagged wallets.

Elsewhere, ZachXBT criticized Circle after about $232 million in stolen USDC crossed from Solana to Ethereum during the April attack. The funds moved through Circle's cross-chain system before the attacker converted much of the value into ETH.

JL later said it was surprising that Drift had not created a recovery bounty. Drift's public record shows that it had announced plans for one. On April 16, the protocol said it was developing a bounty program with support from Arkham and Bybit.

However, the update did not provide a final reward amount, eligibility rules or payment schedule. It remains unclear whether the program became fully active, whether it covered continuing wallet monitoring, or whether independent researchers could claim payment for later tracing work.

Drift also created a user recovery plan separate from stolen-fund tracking. Tether proposed up to $127.5 million in support. Drift plans to issue recovery tokens and fund redemptions through remaining assets, partner capital and future exchange revenue.

The protocol's June investigation update said Mandiant attributed the attack to UNC6862, a North Korean threat group. Drift said the attackers used social engineering and compromised operational access rather than a smart contract flaw. As crypto.news reported, the attackers emptied key vaults within about 12 minutes.

Drift has focused on rebuilding its platform and funding user claims while forensic teams pursue the stolen assets. Its recovery framework states that recovered funds will enter the user recovery pool. The protocol also plans stronger signing controls for critical transactions.

The April attack affected other Solana projects. As previously reported, yield platform Carrot decided to shut down after losses linked to Drift erased most of its deposited value.

The Tornado Cash deposits do not prove that the attacker converted the ETH into usable cash. The deposits remain public, and investigators may still identify later withdrawals. However, they remove a simple wallet-to-wallet trail and make the next phase harder.

Neither Drift nor Solana had publicly responded to ZachXBT's comments at the time of writing. Bybit had not announced whether it reviewed the small deposits shown on Etherscan. The remaining stolen funds and the status of Drift's planned bounty program remain unresolved.

Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com