Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerSwapCryptocurrenciesPricingCrypto APIIntegrationsNewsEarnBlogNFTWidgetsDeFi Portfolio TrackerCrypto Gaming24h ReportPress KitAPI Docs
CoinStats

Drift Protocol exploiter sends $44.4M to Tornado Cash, ZachXBT walks away

2h ago
bullish:

0

bearish:

0

Drift Protocol exploit

Three months of silence ended abruptly when a wallet connected to the Drift Protocol exploit began moving funds again — and the destination was Tornado Cash. On July 23 and 24, the address transferred 23,095.1 ETH, worth roughly $44.4 million, into the Ethereum mixer in rapid-fire batches of 100 ETH, 10 ETH and 1 ETH. For investigators already stretched thin, the timing could not have been worse.

Key takeaways

  • The Drift exploiter moved 23,095.1 ETH (~$44.4 million) into Tornado Cash after roughly three months of wallet inactivity.
  • The same address sent 0.85 ETH to wallets labeled as Bybit deposit addresses during the transfer, according to Etherscan records.
  • Independent investigator ZachXBT said he has no plans to keep tracking the funds, citing the resource demands of monitoring a nine-figure North Korea-linked theft.
  • Mandiant attributed the original attack to UNC6862, a North Korean threat group that used social engineering rather than a smart contract flaw.
  • Drift’s recovery framework pools any recovered funds for user claims and includes plans to issue recovery tokens, though the bounty program’s current status remains unclear.

Resumption of Fund Movements by the Drift Exploiter

Researcher JL, known on-chain as 0xJaelle, first flagged the movement and tagged ZachXBT for attention. On-chain records show the address labeled “Drift Exploiter 4” processed hundreds of transactions over two days. The pace was notable — Onchain Lens reported the attacker was sending 100 ETH batches into the Tornado Cash router several times per minute.

Woven into those transfers were four smaller payments. The same address sent 0.85 ETH to wallets labeled as Bybit deposit addresses, according to Etherscan records and monitoring attributed to PeckShield. Whether those deposits represent an attempt to test exchange-side compliance systems or were simply operational noise is unknown, and Bybit had not publicly commented at the time of writing.

The movement covers only part of the overall theft. Drift’s April recovery update pegged total stolen assets at $295.7 million across JLP, USDC, Bitcoin-linked tokens, SOL, WETH and other assets, with much of the converted value still sitting across four flagged Ethereum wallets. Moving $44.4 million through Tornado Cash does not mean those funds are gone — mixer deposits remain visible on-chain — but it does substantially complicate what comes next.

How Tornado Cash Changes the Investigation

Tornado Cash pools deposits and allows later withdrawals through entirely different addresses. The direct wallet-to-wallet link that investigators rely on disappears. Timing analysis, transaction pattern matching and exchange activity monitoring can still yield leads, but each of those methods requires more data, more time and more staff than simply following a wallet trail.

That technical reality makes the investigative constraints that followed the transfer all the more consequential.

Investigative Challenges and ZachXBT’s Decision to Step Back

ZachXBT’s response was blunt: “Sorry I currently do not have any plans to track these funds further.” He described the task as “difficult for a team and not feasible for a single person,” adding that monitoring a nine-figure North Korea-linked exploit while working toward possible asset freezes would require resources well beyond what one independent researcher can sustain. He also confirmed that Drift was neither a donor nor a client.

The statement drew significant attention on X, partly because it exposed something the crypto security community has long known but rarely states so plainly: the informal layer of independent researchers who monitor high-value thefts operates without guaranteed compensation, and eventually those limits show. When a case stretches past three months and the attacker begins actively obfuscating funds, the economics of continued investigation become difficult to justify without institutional backing.

ZachXBT also criticized Circle after roughly $232 million in stolen USDC crossed from Solana to Ethereum through Circle’s cross-chain system during the April breach, before being converted into ETH. That criticism has not produced any public response from Circle.

Drift Protocol’s Recovery Efforts and Partnership Programs

Drift did announce a recovery bounty program in April alongside Arkham and Bybit, though the details remained thin. On April 16, the protocol said it was developing the program, but the update provided no final reward amount, no eligibility rules and no payment schedule. Whether the program became fully active — or whether it would cover ongoing wallet monitoring by independent researchers — remains unclear.

Separately, Tether proposed up to $127.5 million in support for user recovery. Drift’s broader recovery framework states that any recovered funds enter a user recovery pool, with the protocol also planning to issue Drift recovery tokens and fund redemptions through remaining assets, partner capital and future exchange revenue. The practical timeline for those redemptions has not been publicly confirmed.

Attribution and the Broader Impact of the Exploit

Drift’s June investigation update confirmed that forensic firm Mandiant attributed the attack to UNC6862, a North Korean threat group. The attackers did not exploit a smart contract vulnerability — instead, they ran a social engineering campaign and compromised operational access, ultimately emptying key vaults within about 12 minutes. Drift said it works with law enforcement, Mandiant and blockchain intelligence firms on the ongoing investigation.

The North Korean attribution carries implications beyond the technical. UNC6862’s involvement places the theft inside a geopolitical framework where traditional asset-recovery tools — legal freezes, exchange-level compliance, law enforcement cooperation — face significant jurisdictional constraints. Stolen funds linked to state-sponsored actors have historically proven very difficult to repatriate, and the use of a mixer like Tornado Cash only deepens that problem.

Ripple Effects Across Solana

The Drift Protocol exploit did not affect only one platform. Carrot, a Solana-based yield platform, decided to shut down entirely after losses connected to Drift erased most of its deposited value. That collateral damage illustrates how tightly integrated DeFi protocols can amplify a single attack across an entire ecosystem.

For Drift itself, the path forward involves rebuilding the platform, strengthening signing controls for critical transactions and continuing to fund user claims. The Tornado Cash deposits do not confirm that the attacker has converted the ETH into usable cash — the deposits are public, and investigators may still identify later withdrawal patterns. But they mark a meaningful transition in the case: from a dormant wallet that could be watched, to an active one that has deliberately broken the most readable part of its trail. The next phase of any recovery effort will be considerably harder to prosecute.

FAQ

What recent activity was detected from the Drift Protocol exploiter wallet?

After about three months of inactivity, the exploiter moved 23,095.1 ETH, worth roughly $44.4 million, into Tornado Cash and sent 0.85 ETH to Bybit deposit-labeled wallets, with transfers occurring on July 23 and 24.

Why did independent researcher ZachXBT stop tracking the stolen funds?

ZachXBT cited high resource demands and the absence of institutional support, stating that monitoring a nine-figure North Korea-linked theft while working toward possible asset freezes was not feasible for a single person, and that Drift was not a donor or client.

What is Drift Protocol’s plan for recovering stolen funds?

Drift announced a recovery bounty program with Arkham and Bybit in April, though its full activation status is unclear. The protocol’s recovery framework pools any recovered funds for user claims and includes plans to issue recovery tokens, with Tether also proposing up to $127.5 million in support.

Who has been attributed as responsible for the Drift Protocol attack?

Mandiant attributed the attack to UNC6862, a North Korean threat group that used social engineering and operational access compromise — not a smart contract flaw — to drain key vaults in approximately 12 minutes.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

2h ago
bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.