Executive Summary
Published 6/25/2026, 7:35:53 AM
The KyberSwap attacker, identified by U.S. authorities as Andean Medjedovic, required over two years to launder approximately $40 million (16,100 ETH) of the $48.8 million stolen in November 2023. This extended timeline was a deliberate strategy to overcome the technical limitations of Tornado Cash and evade sophisticated blockchain analytics.
Executive Summary
The laundering process was slowed by the need to maintain a high anonymity set, the protocol's fixed deposit limits (e.g., 100 ETH), and the risk of "value fingerprinting." By spacing out transactions from March 2025 through June 2026, the attacker attempted to blend the stolen funds with legitimate pool activity to prevent investigators from linking deposits to withdrawals.
Laundering Timeline and Major Movements
The attacker began moving significant funds to Tornado Cash nearly 16 months after the initial exploit, continuing well into 2026.
| Date | Event | Amount / Detail |
|---|---|---|
| Nov 22, 2023 | Initial Exploit | $48.8M stolen via "tick manipulation" [Source: https://www.justice.gov/opa/pr/kyberswap-exploit-attacker-charged-48-million-cryptocurrency-theft] |
| Feb 2025 | U.S. Charges | Andean Medjedovic charged with wire fraud and money laundering |
| Mar 15, 2025 | First Major Move | 1,600 ETH (~$3.72M) deposited into Tornado Cash |
| Apr 29, 2026 | Second Major Move | 2,900 ETH (~$6.8M) deposited into Tornado Cash |
| Jun 25, 2026 | Recent Activity | 2,000 ETH (~$4.8M) transferred; total laundered exceeds $40M |
Key Reasons for the Two-Year Duration
1. Anonymity Set and Liquidity Constraints
Tornado Cash's effectiveness relies on the "pool" of funds provided by other users. If an attacker deposits $40M and withdraws it immediately, the unique volume makes the transaction easily traceable. To maintain anonymity, the attacker must wait for enough "clean" deposits from other users to enter the pool, providing the necessary exit liquidity and cover. Moving $40M too quickly would effectively "drain" the pool's clean side, trapping the funds or making them trivial to track.
2. Protocol Deposit Limits
Tornado Cash operates with fixed pool sizes (0.1, 1, 10, and 100 ETH). Laundering $40M (approx. 16,000+ ETH) requires thousands of individual transactions. This "smurfing" technique—breaking large sums into smaller, irregular chunks—is manually intensive and time-consuming but necessary to avoid triggering automated compliance alerts and to fit within the protocol's architecture.
3. Avoiding "Value Fingerprinting"
Blockchain analytics firms like Chainalysis and Elliptic use "value fingerprinting" to cluster transactions. If an attacker deposits 1,337.65 ETH and a similar amount is withdrawn shortly after, the link is obvious. By spreading the $40M over two years and using irregular intervals, the attacker attempted to break the temporal and mathematical links between the stolen assets and the "clean" withdrawals.
4. Multi-Chain Complexity
Before reaching Tornado Cash, the funds were bridged across five different chains (including Arbitrum, Optimism, and Ethereum) and split into dozens of intermediary wallets. This multi-layering strategy was designed to break the direct on-chain link to the exploit but added significant operational complexity and time to the laundering cycle [Source: https://www.chainalysis.com/blog/kyberswap-post-mortem-laundering-analysis].
Conclusion
The two-year window was not a result of incompetence but a calculated response to the throughput bottleneck of privacy protocols and the high efficacy of modern blockchain surveillance. While the attacker successfully moved over 80% of the funds into Tornado Cash by June 2026, the slow pace was required to minimize the risk of immediate deanonymization by federal authorities.