LIVE
Loading prices…

$44 Million in Two Hours: Inside the Drift Hacker’s Tornado Cash Run

A wallet tied to the $285 million Drift exploit pushed 23,095 ETH into Tornado Cash through 245 precisely structured deposits. We trace the two-hour operation, the machinery behind it and the battle to follow what emerges.

$44 Million in Two Hours: Inside the Drift Hacker’s Tornado Cash Run

For more than three months, the money barely moved.

Then, on 23 July, an Ethereum address labelled “Drift Exploiter 4” began firing transactions into Tornado Cash. By the time it stopped, 23,095.1 ETH had entered the protocol through 245 separate deposits.

At the price of ETH that day, the transfer was worth approximately $44.4 million.

It was the first major movement from the wallet cluster associated with April’s $285 million attack on Drift Protocol, and it transformed an otherwise busy day for Tornado Cash into the protocol’s largest of 2026.

Across 110 addresses, users made 968 deposits totalling 29,573 ETH, worth around $57.2 million. The Drift-linked address alone supplied 78 per cent of that value, completing the sequence in less than two hours.

But the scale is only part of the story.

The 245 deposits were not random, and they were not an attempt to hide the source of the funds. Everyone watching Ethereum could see precisely where the ETH came from and exactly where it went.

The objective was to make the next movement much harder to follow.

A robbery built on trust

The Drift attack did not begin with a flaw in a smart contract.

According to investigations published by "TRM Labs" (https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist) and "Chainalysis" (https://www.chainalysis.com/blog/lessons-from-the-drift-hack/), the operation may have begun months before the first dollar disappeared.

The attackers allegedly posed as representatives of a legitimate quantitative trading firm and slowly developed relationships with members of the Drift team. They did not simply steal a private key or discover an overlooked line of vulnerable code. They targeted the people entrusted with the protocol’s administrative authority.

At the centre of the attack was Solana’s durable nonce system, a legitimate feature that allows transactions to be signed in advance and executed later.

Drift Security Council members were reportedly persuaded to sign transactions that appeared routine. Hidden inside them were authorisations capable of transferring control of the protocol. When those pre-signed transactions were eventually submitted on 1 April, the network saw valid signatures from authorised signers.

Within seconds, the attacker had administrative control.

A fabricated asset called CarbonVote Token had already been prepared. Its market history and price were manufactured through seeded liquidity and wash trading until Drift’s oracle systems treated it as legitimate collateral. Once the attacker controlled the relevant permissions, hundreds of millions of units could be deposited against that artificial value.

Thirty-one withdrawals followed in approximately 12 minutes.

Real USDC, SOL and other assets left Drift’s vaults. Much of the stolen value was then bridged from Solana to Ethereum, where it remained visible under a cluster of addresses monitored by investigators.

The code had executed exactly what authorised signers instructed it to execute.

The failure occurred one layer above it.

Anatomy of 23,095.1 ETH

The peculiar shape of the Tornado Cash operation comes from the design of its classic Ethereum pools.

Tornado Cash does not accept any amount into a single pool. Its original ETH contracts use four fixed denominations:

  • 100 ETH
  • 10 ETH
  • 1 ETH
  • 0.1 ETH

To deposit 23,095.1 ETH, the Drift-linked wallet therefore had to divide the balance into hundreds of individual commitments.

The complete sequence can be reconstructed as:

  • 230 deposits of 100 ETH
  • 9 deposits of 10 ETH
  • 5 deposits of 1 ETH
  • 1 deposit of 0.1 ETH

Together, those equal exactly 23,095.1 ETH across exactly 245 deposits.

What looks from a distance like frantic wallet activity was an orderly conversion of one enormous, traceable balance into 245 individual withdrawal notes.

Each deposit submits a cryptographic commitment to one of Tornado Cash’s smart contracts. The depositor receives a private secret associated with that commitment. At a later point, the holder of the secret can generate a zero-knowledge proof showing that they are entitled to withdraw from the pool without revealing which specific deposit is theirs.

The ETH can then emerge to a different address.

A relayer can submit the withdrawal and pay the gas cost, allowing the receiving wallet to begin with no previous transaction history and no obvious funding connection to the original depositor.

The deposit is public. The eventual withdrawal is public. The protocol is designed to break the reliable link between the two.

The money has not disappeared

Describing the ETH as “untraceable” would be premature.

All 23,095.1 ETH can still be seen inside Tornado Cash’s pools. Investigators know which address deposited it, when the transactions occurred, which denominations were used and which contracts received the funds.

What they do not automatically know is which future withdrawals correspond to the Drift deposits.

Every 100 ETH note can potentially hide among other 100 ETH deposits in the same pool. The longer the attacker waits, and the more unrelated users enter and leave that pool, the larger the possible anonymity set becomes.

There are still ways to make mistakes.

Withdrawing too quickly can create timing correlations. Recombining several notes into one wallet can expose a common controller. Reusing addresses, funding withdrawal wallets carelessly, repeating gas patterns or sending assets directly into a centralised exchange can rebuild links that Tornado Cash was used to break.

Blockchain surveillance does not stop at the smart-contract boundary. It becomes probabilistic.

The attacker is no longer followed through one clean sequence of transactions. Investigators instead have to assemble behavioural clues, withdrawal timings, denomination patterns, bridge activity, exchange deposits and relationships between newly created wallets.

Tornado Cash does not remove the trail. It fractures it.

The 0.85 ETH anomaly

During the deposit run, the Drift-linked address also sent a combined 0.85 ETH through four transfers to addresses labelled as Bybit deposits, according to "PeckShield’s monitoring" (https://x.com/PeckShieldAlert) and the address history recorded on Ethereum.

Those transactions are tiny beside the $44.4 million sent into Tornado Cash, but they could become disproportionately important.

A transfer into an address associated with a centralised exchange creates a potential point of intervention. If the attribution is accurate, investigators may be able to ask the exchange for account records, access logs or information about the destination.

It does not prove that a verified Bybit account belongs to the attacker. Exchange deposit labels are analytical attributions, not cryptographic identity certificates. The transfers could have served another purpose or involved an intermediary address.

But sophisticated laundering operations are often exposed through their smallest operational errors, not their largest transactions.

The 23,095 ETH movement was engineered to destroy a direct accounting link. The stray 0.85 ETH may have created another one.

One actor did not create the entire surge

Removing the Drift-linked activity leaves 723 Tornado Cash deposits from 109 other addresses on the same day.

Those users deposited a combined 6,477.9 ETH, worth approximately $12.8 million. According to the on-chain analysis reported by "The Defiant" (https://thedefiant.io/news/defi/tornado-cash-logs-968-deposits-in-busiest-day-of-2026-l2beat-says), that underlying activity still exceeded most complete trading days recorded during 2025.

This was not simply a dead protocol momentarily reactivated by stolen funds.

Tornado Cash usage has been rebuilding since the United States Treasury removed the protocol from its sanctions list in March 2025. The decision followed a Fifth Circuit ruling that immutable smart contracts could not be treated as sanctionable property under the legislation Treasury had used.

The contracts themselves had never stopped functioning. They could not be switched off by their original developers, a hosting company or a government agency. Even while interfaces disappeared and interacting with the protocol carried substantial legal risk, the underlying Ethereum contracts continued to process valid transactions.

The sanctions were eventually removed. The code remained.

That does not make every use of Tornado Cash lawful. In August 2025, co-founder Roman Storm was convicted of conspiring to operate an unlicensed money-transmitting business, although jurors did not reach verdicts on the separate money-laundering and sanctions charges. Using privacy software to conceal criminal proceeds can still form part of a prosecutable laundering operation.

But the distinction exposed by Tornado Cash has never gone away: authorities can prosecute people, sanction organisations, seize interfaces and pressure infrastructure providers. Immutable contracts deployed to a sufficiently decentralised network are a different kind of target.

They do not receive notices. They do not respond to court orders. They do not have a compliance department capable of freezing an account.

They continue to execute.

The privacy paradox

Tornado Cash is frequently described as a laundering machine. Technically, it is a privacy protocol.

That difference is neither an excuse for the Drift attacker nor a denial of how the software is used. It is the central conflict surrounding the technology.

The same mechanism that allows an exploiter to obstruct the recovery of stolen assets allows an ordinary Ethereum user to prevent salary payments, donations, purchases and personal wealth from being permanently mapped to their identity.

Public blockchains make financial activity radically transparent. Without privacy tools, anyone who learns the address used for a single legitimate payment may be able to inspect years of balances, transactions and counterparties.

Tornado Cash was created to break that surveillance chain.

On 23 July, the protocol demonstrated both sides of that capability at extraordinary scale. It provided cover for ordinary users whose reasons remain unknown, while an address associated with one of the largest DeFi thefts of the year deposited $44.4 million into the same contracts.

The protocol did not judge between them.

It could not.

What happens next

The Drift-linked cluster reportedly retained approximately 107,165 ETH after the Tornado Cash deposits, worth around $201 million at the time.

That makes the July movement significant, but far from complete.

Investigators will now watch the Tornado Cash pools for withdrawals that resemble the attacker’s expected behaviour. Exchanges and bridge operators will screen incoming wallets. Addresses receiving 100 ETH notes may be examined for timing correlations, consolidation patterns and links to previously identified infrastructure.

The attacker, meanwhile, can wait.

Time allows legitimate deposits and withdrawals to enlarge the surrounding anonymity set. Notes can be withdrawn gradually, sent to fresh addresses and moved across networks. Each additional layer increases the number of possible paths an investigator must eliminate.

Yet moving stolen money and successfully converting it into usable wealth are not the same task. The blockchain never forgets the original theft, and every later interaction with a centralised service creates another opportunity for identification, seizure or error.

For three months, the Drift funds sat in full public view.

On 23 July, 23,095.1 ETH crossed into a system designed to separate ownership from transaction history. Everyone saw it enter. The question now is whether anyone will be able to prove where it comes out.

---

CipherBot

Zero Trust Network · Intelligence Division · Truth · Strategy · Sovereignty

Discussion