The transfers mark the first major movement in four months after the $285 million exploit, with investigators linking the operation to laundering patterns seen in past North Korea-connected cases.
A wallet tied to the Drift Protocol exploit transferred about $44.4 million, or 23,095.1 ETH, to Tornado Cash, with a separate 0.85 ETH transaction sent to Bybit. The activity is the first significant movement of funds from the April theft in four months and signals that laundering of the roughly $285 million haul has resumed. PeckShield identified the sending address as linked to the exploit, while Etherscan records show the wallet 0xbDdAE987FEe930910fCC5aa403D5688fB440561B, labeled “Drift Exploiter 4,” split the Tornado Cash deposits across several transactions. Arkham Intelligence also groups the address under its “Drift Protocol Exploiter” cluster of nearly twenty wallets suspected of involvement. Investigators have not conclusively attributed the attack, but several blockchain analytics firms have associated the operation with North Korean state-sponsored hackers or infrastructure used in prior DPRK operations. The latest transfers fit a pattern described by Chainalysis in its 2026 Crypto Crime Report, which says North Korea-linked groups often leave stolen assets dormant for weeks before using bridges, wallets and privacy tools to complicate recovery. The small Bybit transfer may have been a test transaction ahead of larger cash-out attempts. The April exploit hit Drift, described as the biggest perpetual futures (crypto derivatives without expiry) trading platform on Solana, and cut its total value locked by more than 50%, according to PeckShield. Investigators later said the theft stemmed from a months-long social engineering campaign rather than a smart contract (self-executing blockchain code) flaw. Chainalysis said the attackers posed for about six months as representatives of a quantitative trading firm, attended industry events, met Drift contributors and deposited more than $1 million into the protocol before compromising developer devices. Chainalysis said the attackers then secured pre-signed approvals from two of Drift’s five Security Council members by exploiting Solana’s durable nonce feature. They also created CarbonVote Token (CVT), inflated its price through wash trading and used it as collateral to expand borrowing limits before draining the protocol in 31 withdrawals over roughly 12 minutes. The fallout spread beyond Drift, with Chainalysis reporting that at least 20 Solana-based projects were disrupted because they used Drift’s vault structure as a yield source. Analysts at Chainalysis, Elliptic and Merkle Science say wallet clustering and cross-chain tracing can still follow parts of the funds even after they pass through Tornado Cash, though recovery becomes much harder once a mixer is used.