NewsCryptoDrift Protocol Exploiter Moves $44M Through Tornado Cash After Months of Inactivity

Drift Protocol Exploiter Moves $44M Through Tornado Cash After Months of Inactivity

Author: crypto.news·

Key Takeaways

  • A wallet tied to the Drift Protocol exploit transferred approximately 23,095 ETH worth $44.4 million into Tornado Cash between July 23 and 24 after remaining largely inactive since the April attack.
  • Independent on-chain investigator ZachXBT stated he would not continue tracking the stolen funds without institutional backing, describing the effort as infeasible for a single person.
  • Mandiant attributed the original April attack to UNC6862, a North Korean threat group that used social engineering and compromised operational access rather than a smart contract vulnerability.
  • Drift announced plans for a bounty program in April with support from Arkham and Bybit, but final reward amounts, eligibility rules, and the program's operational status remain undisclosed.
  • Tether proposed up to $127.5 million in support of Drift's user recovery plan, which aims to fund redemptions through remaining assets, partner capital, and future exchange revenue.
Drift Protocol Exploiter Moves $44M Through Tornado Cash After Months of Inactivity

A wallet tied to the $285 million Drift Protocol exploit has transferred 23,095.1 Ether, worth approximately $44.4 million, into Tornado Cash after nearly three months of dormancy.

According to Etherscan records and monitoring attributed to PeckShield, the same address also sent 0.85 ETH to wallets labeled as Bybit deposit addresses. The transfers began on July 23 and continued into July 24.

Researcher JL, known on X as 0xJaelle, flagged the movement and tagged on-chain investigator ZachXBT. ZachXBT responded that he did not intend to continue tracking the funds without institutional support.

The drift exploiter moving funds finally. Something @zachxbt and @tayvano_ may want to keep an eye out. — JL (@0xJaelle) July 24, 2026

Drift Exploiter Empties an Ethereum Wallet

The Etherscan address labeled "Drift Exploiter 4" processed hundreds of transactions during the movement. Records show repeated deposits of 100 ETH, 10 ETH, and 1 ETH into the Tornado Cash router. Four additional transfers totaling 0.85 ETH were sent to addresses identified as Bybit deposit wallets.

Onchain Lens first reported that the attacker had resumed activity, sending 100 ETH batches into the mixer several times per minute. The wallet had remained largely inactive since the April attack.

Tornado Cash pools deposits and allows later withdrawals through different addresses, weakening the direct public link between sending and receiving wallets. Investigators can still use timing analysis, transaction patterns, and exchange activity, but the process demands more data and personnel. Mixers are also closely watched by exchanges and compliance teams because deposits from flagged exploit wallets can affect whether later funds are frozen or reported when they touch regulated venues.

The movement represents only a portion of the original theft. Drift's April recovery update valued stolen assets at $295.7 million across JLP, USDC, Bitcoin-linked tokens, SOL, WETH, and other assets. The protocol stated that much of the converted value remained across four flagged Ethereum wallets.

ZachXBT Cites Cost of Tracking North Korea-Linked Funds

ZachXBT wrote, "Sorry I currently do not have any plans to track these funds further." He explained that monitoring a nine-figure North Korea-linked exploit and working toward possible freezes would require resources beyond what one independent investigator can provide. He described the task as "difficult for a team and not feasible for a single person." ZachXBT also noted that Drift was not a donor or client.

His response on X drew attention to the cost of investigations that can stretch over months. However, the comments do not indicate that no organization is monitoring the wallets. Drift has stated it works with law enforcement, Mandiant, and blockchain intelligence firms. Etherscan continues to label the address, and exchanges can review deposits connected to flagged wallets.

Separately, ZachXBT criticized Circle after approximately $232 million in stolen USDC crossed from Solana to Ethereum during the April attack. The funds moved through Circle's cross-chain system before the attacker converted much of the value into ETH. That bridge activity matters for investigators because once stolen assets are consolidated on another chain and converted, recovery efforts depend on cross-chain records, issuer actions, exchange controls, and continued wallet surveillance rather than a single protocol's internal data.

Drift Had Announced a Recovery Bounty Program

JL later expressed surprise that Drift had not created a recovery bounty. However, Drift's public record shows the protocol had announced plans for one. On April 16, Drift said it was developing a bounty program with support from Arkham and Bybit. The update did not specify a final reward amount, eligibility rules, or payment schedule. It remains unclear whether the program became fully active, whether it covered continuing wallet monitoring, or whether independent researchers could claim payment for later tracing work.

Drift also established a user recovery plan separate from stolen-fund tracking. Tether proposed up to $127.5 million in support. Drift plans to issue recovery tokens and fund redemptions through remaining assets, partner capital, and future exchange revenue.

The protocol's June investigation update said Mandiant attributed the attack to UNC6862, a North Korean threat group. Drift stated the attackers used social engineering and compromised operational access rather than a smart contract flaw. The attackers emptied key vaults within approximately 12 minutes. The finding placed the incident among a series of crypto thefts in which operational security, signer access, and internal controls became as important to recovery discussions as smart contract review.

Recovery Continues as the Trail Becomes Harder to Follow

Drift has focused on rebuilding its platform and funding user claims while forensic teams pursue the stolen assets. Its recovery framework states that recovered funds will enter the user recovery pool. The protocol also plans stronger signing controls for critical transactions.

The April attack affected other Solana projects. Yield platform Carrot decided to shut down after losses linked to Drift erased most of its deposited value.

The Tornado Cash deposits do not prove the attacker has converted the ETH into usable cash. The deposits remain public, and investigators may still identify later withdrawals. However, they remove a simple wallet-to-wallet trail and make the next phase of tracking more difficult.

Neither Drift nor Solana had publicly responded to ZachXBT's comments at the time of writing. Bybit had not announced whether it reviewed the small deposits shown on Etherscan. The remaining stolen funds and the status of Drift's planned bounty program remain unresolved.