Aztec Exploiter Moves 500 ETH to Tornado Cash in Gradual Laundering Strategy
Key Takeaways
- •The attacker behind the June Aztec Connect exploit has routed a total of 500 ETH through Tornado Cash, equivalent to approximately 55% of the 909 ETH stolen in the original attack.
- •The hacker has employed a deliberate, phased laundering strategy with small deposits spaced weeks apart, contrasting sharply with the rapid bulk transfers seen in incidents like the 2022 Beanstalk exploit.
- •The original June 14 attack siphoned approximately $2.19 million from deprecated Aztec Connect contracts by exploiting a flaw in proof verification and settlement boundary processes rather than the protocol's underlying cryptography.
- •TRM Labs recorded 207 cryptocurrency hacks in the first half of 2026 totaling $972 million in losses, the highest number recorded for that period despite a decline in average value per incident.
- •The U.S. Treasury lifted sanctions against Tornado Cash on March 21, 2025, after a Fifth Circuit ruling determined that immutable smart contracts are not property under OFAC jurisdiction.

The attacker behind the June exploit of Aztec's deprecated Connect rollup has deposited an additional 300 ETH into Tornado Cash, bringing the total moved through the mixer to 500 ETH, according to blockchain security firm PeckShield.
The significance of the transfers extends beyond their cumulative value. The hacker has now routed approximately 55% of the 909 ETH stolen in the original attack through Tornado Cash, but has done so in varying amounts rather than a single large transaction. This patterned timing suggests a deliberate exit strategy that avoids the rapid laundering approach seen in other major cryptocurrency exploits.
A Slow Drip Into the Mixer
The most recent deposit of 300 ETH, valued at approximately $572,100 at the time, was sent to Tornado Cash on August 8, PeckShield reported. On July 2, the firm flagged an earlier deposit of 145 ETH worth roughly $227,650, which had brought the running total to 200 ETH.
Rather than moving the stolen ETH in one transaction, the attacker has deposited funds in small batches, with the most recent deposit occurring 37 days after the previous one.
#PeckShieldAlert The @aztecnetwork Private Rollup Bridge exploiter-labeled address has deposited 145 ETH ($227,650) into #TornadoCash . So far, the exploiter has deposited a total of 200 ETH into #TornadoCash . pic.twitter.com/QJpfsdwtTS — PeckShieldAlert (@PeckShieldAlert) July 2, 2026
This approach stands in stark contrast to the 2022 Beanstalk incident. According to Merkle Science, those attackers executed 270 transfers totaling 24,930 ETH through Tornado Cash, with most transfers similar in size and executed within seconds of each other.
The Aztec exploiter's slower method does not fully conceal the funds from scrutiny. While Tornado Cash was designed to sever the on-chain link between deposits and withdrawals, transaction timing, wallet behavior, and activity outside the mixer can still expose information. TRM Labs reported that it has tracked funds hidden by the mixer using behavioral and timing correlation, anonymity set analysis, and off-ramp identification.
Origins of the Stolen Funds
The stolen funds trace back to June 14, when an attacker siphoned approximately $2.19 million from obsolete Aztec Connect rollup contracts in a single transfer. According to Blockaid, the stolen assets included 909 ETH, 270,513 DAI, 168 wstETH, and other tokens.
A second attack followed just one day later, targeting the same legacy system and resulting in the theft of approximately $88,000 in residual assets. Blockaid reported that the attacker used the same settlement method to exploit remaining bridge positions.
Notably, the exploit did not compromise Aztec's underlying cryptography. Instead, Blockaid identified a flaw in the proof verification and settlement boundary processes that allowed the attacker to generate balances without corresponding deposits backing them.
Aztec Connect had already been deprecated, and Aztec Labs no longer held the administrative keys for the affected immutable contracts. The current Aztec Network and AZTEC token were not affected by the incident.
Why Stolen Funds Still Flow to Tornado Cash
The Aztec case illustrates a broader trend in cryptocurrency: the number of attacks is increasing even as the average value per incident declines.
According to TRM Labs, there were 207 crypto hacks in the first half of 2026 — the highest number recorded for that period. Total losses reached $972 million, less than half of the $2.3 billion stolen during the first half of 2025. Smart-contract exploits accounted for 125 incidents in 2026, with a median loss of approximately $219,000.
Tornado Cash remains a central component of cryptocurrency laundering infrastructure. TRM reported in June that the mixer accounted for 20% of worldwide mixer activity in 2026 and remained the leading mixer on Ethereum-based networks, despite a significant decline in its market share following U.S. sanctions imposed in 2022.
Academic research reinforces the platform's prominence. A study by researchers at the University of Birmingham and the University of Sydney found that Tornado Cash was used in 78.33% of all hacking events on the Ethereum blockchain during the period examined.
The legal landscape has since shifted. The U.S. Treasury lifted its sanctions against Tornado Cash on March 21, 2025, following a Fifth Circuit ruling that immutable smart contracts are not considered property under the jurisdiction of the Office of Foreign Assets Control (OFAC).
For DeFi participants, the Aztec incident underscores a systemic issue: immutable, deprecated contracts can remain economically significant—and vulnerable—long after a protocol is abandoned. With only 55% of the stolen ETH routed through Tornado Cash so far, the remaining 409 ETH represents a key monitoring point for on-chain analysts tracking the ongoing laundering process. The case highlights the persistent challenge of securing legacy funds even as the industry advances to new architectures.