Drift attacker resumes transfers, moving 23,095.1 ETH into Tornado Cash

Drift attacker resumes transfers, moving 23,095.1 ETH into Tornado Cash

Fresh on-chain activity shows wallets tied to Drift Protocol’s April 2026 exploit sent about $44.4 million in ETH to Tornado Cash and a small transfer to Bybit-linked addresses after roughly three months of inactivity.

BTC
ETH
SOL

Fact Check
The originating on-chain analytics source (OnchainLens X post, citing Arkham data) directly states that after three months of inactivity the Drift Protocol $285M exploiter began depositing ETH in rapid 100 ETH batches into the Tornado Cash Router. This is reproduced consistently by PANews and BlockBeats. The underlying $285M April 2026 Drift Protocol Solana exploit is independently confirmed by Chainalysis. All specific claim elements — ~3-month dormancy, resumption of transfers, 100 ETH batch sizes, and Tornado Cash routing — match the primary source.
Summary

Wallets tied to the April 2026 exploit of Drift Protocol have resumed moving funds after roughly three months of dormancy, sending 23,095.1 ETH worth about $44.4 million into Tornado Cash and 0.85 ETH to wallets labeled as Bybit deposit addresses. Transfers began on July 23 and continued into July 24, with on-chain records showing repeated 100 ETH, 10 ETH and 1 ETH deposits into the mixer. Researcher JL, known as 0xJaelle, flagged the movement and tagged ZachXBT, who said he did not plan to keep tracking the funds without institutional support, describing the work required to monitor and potentially freeze a nine-figure North Korea-linked theft as beyond the capacity of one independent investigator. The movement covers only part of the original theft, which Drift valued in April at $295.7 million across JLP, USDC, Bitcoin-linked tokens, SOL, WETH and other assets. Drift has said it is working with law enforcement, Mandiant and blockchain intelligence firms, and had previously announced plans for a recovery bounty program with support from Arkham and Bybit, though key details of that program remained unclear. Drift’s June investigation update said Mandiant attributed the attack to UNC6862 and that the breach stemmed from social engineering and compromised operational access rather than a smart contract flaw, complicating recovery efforts as the trail becomes harder to follow.

Terms & Concepts
  • Tornado Cash: An Ethereum mixing service that pools deposits and later enables withdrawals through different addresses, making direct wallet tracing more difficult.
  • Recovery bounty program: A reward scheme intended to encourage researchers or investigators to help trace, identify or recover stolen assets.
  • Smart contract flaw: A bug or vulnerability in onchain code that can be exploited to steal or misuse funds.