Back to news
NewsMarkets

Drift's $285M Exploiter Broke a Three-Month Silence and Sent $44.4M Into Tornado Cash. ZachXBT Says He Is Stepping Back

Tony Rabbit 3 days ago 74 views 0 shares
Drift's $285M Exploiter Broke a Three-Month Silence and Sent $44.4M Into Tornado Cash. ZachXBT Says He Is Stepping Back

The wallets behind the largest DeFi exploit of 2026 went quiet for almost three months. This week one of them moved. On July 23 and 24, an address tied to April's $285 million Drift Protocol hack pushed 23,095 ETH, worth about $44.4 million, into Tornado Cash, the Ethereum mixer that severs the on-chain trail. We converted the flow at the live ETH price to check the math, and the number holds. What is striking is how little of the haul it represents, and who just publicly stepped back from chasing it.

At an ETH price of $1,906, those 23,095 ETH are worth $44.0 million, in line with the reported $44.4 million. And it is only a slice of what was taken: at the reported $44.4 million, this Tornado batch equals just 15.6% of the $285 million drained in April. The other roughly $240 million has not moved. The wallet that fed the mixer, one of a cluster of addresses investigators tie to the exploit, now reads 0.0038 ETH on-chain after 249 outbound transactions, consistent with a near-total drain of that address; the unmoved millions sit in other wallets in the cluster.

The laundering is a fraction of the haul

Drift $285M exploit: only $44.4M, 15.6%, moved to Tornado Cash this week
The Tornado Cash deposit this week accounts for about a sixth of the total drained from Drift in April. Chart by DEXTools News; ETH value read at the live price.
Drift exploit, by the numbersFigure
Total drained (April 1, 2026)~$285M
Moved to Tornado Cash (July 23-24)23,095 ETH
That batch in USD (at $1,906/ETH)~$44.0M
Share of the haul (at reported $44.4M)15.6%
Still not moved~$240M
Flagged wallet balance now0.0038 ETH

What happened in April

Drift Protocol, the largest decentralized perpetual-futures exchange on Solana, was drained of roughly $285 million on April 1, 2026. It was not a smart-contract bug. According to Mandiant, the attack was the work of UNC6862, a North Korean threat group that used social engineering to gain access rather than exploiting a flaw in the code. That detail matters: it puts the theft in the same bucket as the state-linked operations that have defined the biggest crypto heists of the last two years, and it is why attribution keeps pointing at Pyongyang.

The theft happened on Solana, but the money did not stay there. In the weeks after the attack, investigators tracked the proceeds as they were swapped and bridged into ETH and consolidated across a cluster of Ethereum addresses, standard practice for large hauls because Ethereum is where the deep mixer liquidity lives. That cluster is why this week's deposits, and our own wallet reads, happen on Ethereum rather than Solana.

Why ZachXBT walking away is the real signal

For most of the past three months the funds sat still, and independent investigator ZachXBT was among those watching the addresses. After this week's move into Tornado Cash, he signaled he would not keep tracking it solo, describing the job of monitoring a nine-figure, North Korea-linked theft, while working toward any possible asset freeze, as difficult even for a team and not feasible for one person.

That is a candid admission about the limits of open-source tracing. Once funds enter a mixer, following them requires sustained, well-resourced analysis, the kind that law enforcement and specialist firms are built for and a lone researcher is not. When the field's most prominent independent sleuth says a case is beyond one person, it is a marker of how the economics of laundering favor the attacker at this scale.

What to watch

Three things. First, whether the remaining ~$240 million starts moving in similar batches, mixer deposits tend to come in tranches to avoid overwhelming liquidity. Second, whether Tornado Cash's post-sanctions status shapes how exchanges treat any funds that emerge downstream, since deposits from a sanctioned mixer linked to a North Korean group are exactly what compliance desks screen for. Third, whether any coordinated freeze materializes; the honest read from this week is that the burden has shifted from independent investigators to agencies with subpoena power.

The timeline so far

DateEvent
April 1, 2026Drift Protocol drained of ~$285M, the largest DeFi exploit of the year
April 2026Mandiant attributes the attack to UNC6862, a North Korean group using social engineering
April to mid-JulyFunds sit essentially dormant for almost three months
July 23-2423,095 ETH (~$44.4M) deposited into Tornado Cash
July 26Flagged wallet reads 0.0038 ETH after 249 outbound transactions; ZachXBT steps back

The North Korea laundering playbook

The rhythm of this case fits how state-linked groups have handled large hauls before. After the $625 million Ronin bridge theft in 2022, funds attributed to Lazarus Group flowed into Tornado Cash in steady tranches over a period of weeks. After the record $1.46 billion Bybit theft in February 2025, the laundering ran even faster, with the bulk of the ETH moved within days. Against that history, Drift's three months of dormancy followed by a single $44 million burst reads like the patient end of the spectrum, which usually means the operators feel no pressure.

Mechanically, a sum like 23,095 ETH does not enter Tornado Cash as one transaction. The mixer takes deposits in fixed-size pools, so a batch this large arrives as hundreds of separate deposits, which is why these moves show up as visible bursts on-chain rather than a single transfer. It is also why the remaining ~$240 million still matters for defenders: every future burst is observable the moment it starts, and researchers have repeatedly shown that careless, quickly-withdrawn mixer funds can be re-linked by timing analysis. The trail is harder now, not gone.

The bottom line

The Drift exploiter finally blinked, but only moved a sixth of the money, and the person most associated with tracking it just said the rest is bigger than one investigator can chase. The stolen $285 million is not recovered. This week it simply got harder to follow.

Data note. The 23,095 ETH Tornado Cash deposit is dated July 23-24, 2026 per on-chain reporting; DEXTools News converted it at the live ETH price of $1,906 (about $44.0 million) and independently read the current balance (0.0038 ETH) and outbound transaction count (249) of the wallet that fed the deposits, one of several addresses investigators tie to the exploit, from a public Ethereum node on July 26, 2026. The $285 million total, the North Korea attribution to UNC6862 (Mandiant) and ZachXBT's comments reflect public reporting. Historical comparisons (Ronin 2022, Bybit 2025) reflect public reporting and attribution. This article is for information only and is not financial advice.

Frequently asked questions

How much did the Drift exploiter move to Tornado Cash?

On July 23-24, 2026, a wallet tied to the Drift Protocol exploit sent 23,095 ETH into Tornado Cash. At an ETH price of about $1,906 that is roughly $44.0 million, in line with the reported $44.4 million. It represents about 15.6% of the $285 million drained from Drift in April 2026.

How much of the stolen Drift funds is still unmoved?

About $240 million of the roughly $285 million taken has not moved. This week's Tornado Cash deposit was only the first large transfer after nearly three months of dormancy. A wallet flagged as tied to the exploit now reads 0.0038 ETH on-chain after 249 outbound transactions.

Who was behind the Drift Protocol hack?

Mandiant attributed the April 1, 2026 exploit to UNC6862, a North Korean threat group that used social engineering rather than a smart-contract flaw. Drift is the largest decentralized perpetual-futures exchange on Solana, and the roughly $285 million loss was the largest DeFi exploit of the year.

Why did ZachXBT stop tracking the Drift funds?

Independent investigator ZachXBT signaled he would not continue tracing the funds alone, describing the monitoring of a nine-figure, North Korea-linked theft, alongside any push for asset freezes, as difficult for a team and not feasible for a single person. It highlights the limits of open-source tracing once funds enter a mixer.

Related reading