Skip to main content
BTC / USDT107,400+2.19%ETH / USDT3,840+2.13%SOL / USDT182.40−1.99%BNB / USDT652.30+0.66%XRP / USDT2.2150+1.61%DOGE / USDT0.3850−1.79%TON / USDT5.240+2.34%AVAX / USDT42.60−2.07%LINK / USDT22.40+2.28%ADA / USDT1.0520−1.68%TRX / USDT0.3300+0.92%DOT / USDT8.420+2.93%BTC / USDT107,400+2.19%ETH / USDT3,840+2.13%SOL / USDT182.40−1.99%BNB / USDT652.30+0.66%XRP / USDT2.2150+1.61%DOGE / USDT0.3850−1.79%TON / USDT5.240+2.34%AVAX / USDT42.60−2.07%LINK / USDT22.40+2.28%ADA / USDT1.0520−1.68%TRX / USDT0.3300+0.92%DOT / USDT8.420+2.93%
Pricing
cryptoJul 27, 2026, 8:03 PM

Drift’s $285M Hacker Breaks Silence With a Big Move

A wallet linked to the $285 million Drift Protocol exploit transferred over $44 million in ETH to Tornado Cash, marking the first major movement of stolen funds in three months.

A wallet associated with the $285 million Drift Protocol exploit has begun moving stolen funds after three months of dormancy. Blockchain security firm PeckShield flagged transactions starting July 23, 2026, in which 23,095.1 ETH — worth approximately $44.4 million — was sent to the privacy mixer Tornado Cash. An additional 0.85 ETH was transferred to the exchange Bybit.

The wallet, labeled "Drift Exploiter 4" on Etherscan at address 0xbDdAE987FEe930910fCC5aa403D5688fB440561B, belongs to a cluster of nearly twenty wallets identified by Arkham Intelligence as connected to the April exploit. The Tornado Cash deposits were split across multiple transactions.

Drift, the largest perpetual futures trading platform on Solana, lost over 50% of its total value locked in the April hack. Investigators determined the exploit was driven by a months-long social engineering campaign rather than a smart contract flaw, according to Chainalysis. Attackers spent roughly six months posing as representatives of a quantitative trading firm, attended industry events, met Drift contributors, and deposited over $1 million into the protocol to build trust before compromising developer devices.

The exploit leveraged Solana's durable nonce feature to obtain pre-signed approvals from two of Drift’s five Security Council members. The attackers created a low-value token called CarbonVote Token, inflated its price through wash trading, used it as collateral to raise borrowing limits, and drained the protocol in 31 withdrawals over about 12 minutes.

Multiple blockchain analytics firms, including Elliptic and TRM Labs, have linked the operation’s infrastructure to patterns previously associated with North Korean state-sponsored hackers, though attribution remains unconfirmed. Drift’s post-mortem identified the group as UNC4736 with medium confidence. Chainalysis noted that DPRK-linked groups typically hold stolen assets dormant before using bridges, wallets, and privacy tools to obscure recovery paths.

Tornado Cash was sanctioned by the US Treasury in 2022 but removed from the sanctions list in March 2025, yet it continues to be used for laundering. Firms such as Chainalysis and Elliptic say wallet clustering and cross-chain analysis can still trace portions of mixed transactions. The 0.85 ETH transfer to Bybit may have been a test before larger cash-out attempts. At least 20 Solana-based projects experienced disruptions because they relied on Drift’s vault structure for yield. The latest deposits signal that the laundering process has resumed, making full recovery of the $285 million significantly more difficult.

Source: FinanceFeeds