How did 3200 ETH get successfully laundered
Published 7/5/2026, 4:53:07 PM
The 3,200 ETH laundering incident (approximately $5.5 million) occurred between July 2 and July 3, 2026, involving a sophisticated multi-stage operation that leveraged Tornado Cash and Circle's Cross-Chain Transfer Protocol (CCTP) to move funds to KuCoin via the Arbitrum network [Source: https://www.kucoin.com/news/flash/zachxbt-discloses-5-5m-eth-theft-via-tornado-cash-and-cctp-bridge].
Answer
The laundering operation was characterized by a "textbook" decentralized money laundering route, moving from initial theft to a centralized exchange exit point.
1. Method and Fund Flow
The operation followed a five-stage process to obfuscate the origin of the funds:
- Initial Theft: The funds originated from two separate private key compromise incidents [Source: https://bingx.com/en/flash-news/post/zachxbt-says-hacker-moved-eth-via-tornado-cash-laundered-m-through-circle-cctp-to-arbitrum].
- Mixing: The attacker withdrew 3,200 ETH from Tornado Cash to break the direct on-chain link to the theft [Source: https://www.kucoin.com/news/flash/zachxbt-discloses-5-5m-eth-theft-via-tornado-cash-and-cctp-bridge].
- Cross-Chain Bridging: The ETH was converted to USDC and moved from Ethereum Mainnet to Arbitrum using Circle's CCTP.
- Distribution: Once on Arbitrum, the funds were split across seven distinct deposit addresses [Source: https://bingx.com/en/flash-news/post/zachxbt-says-hacker-moved-eth-via-tornado-cash-laundered-m-through-circle-cctp-to-arbitrum].
- Final Exit: The distributed funds were deposited into KuCoin, an exchange previously cited by the DOJ for systemic AML/KYC deficiencies.
2. Technical Details of CCTP Exploitation
The use of CCTP was a critical technical choice for the launderers. Unlike traditional bridges that lock and unlock assets, CCTP uses a burn-and-mint mechanism:
- Native Transfer: USDC is burned on the source chain (Ethereum) and a fresh, native version is minted on the destination chain (Arbitrum).
- Permissionless Nature: The protocol is permissionless, allowing the attacker to integrate it into their laundering script without requiring approval from Circle, provided the funds were not blacklisted at the moment of the burn.
- Speed and Liquidity: CCTP allowed the attacker to move $5.5 million in a single, highly liquid asset (USDC) without the slippage or "wrapped asset" risks associated with third-party bridges.
3. Incident Summary Table
| Metric | Detail |
|---|---|
| Total Amount | 3,200 ETH (~$5.5 million USD) |
| Date of Operation | July 2–3, 2026 |
| Primary Tools | Tornado Cash, Circle CCTP |
| Destination Chain | Arbitrum |
| Exit Point | KuCoin (7 deposit addresses) |
| Attribution | ZachXBT, Huoxing Finance |
The incident highlights a growing trend where attackers favor native cross-chain protocols like CCTP over traditional bridges to move large volumes of stolen assets across ecosystems quickly.
Evidence Snippets
Claim: 3,200 ETH was laundered via CCTP to KuCoin on Arbitrum.
- Evidence snippet: "A sophisticated money laundering operation successfully moved approximately 3,200 ETH (~$5.5 million) through Circle's Cross-Chain Transfer Protocol (CCTP) to deposit addresses on the Arbitrum network, ultimately reaching KuCoin. The operation occurred between July 2-3, 2026."
- URL: [Source: https://www.kucoin.com/news/flash/zachxbt-discloses-5-5m-eth-theft-via-tornado-cash-and-cctp-bridge]
Claim: The funds originated from private key compromises and were mixed via Tornado Cash.
- Evidence snippet: "Initial Withdrawal: 3,200 ETH withdrawn from Tornado Cash mixer (July 2-3, 2026). Source of Funds: Tied to two private key compromise incidents."
- URL: [Source: https://bingx.com/en/flash-news/post/zachxbt-says-hacker-moved-eth-via-tornado-cash-laundered-m-through-circle-cctp-to-arbitrum]
Claim: The funds were distributed across seven Arbitrum addresses.
- Evidence snippet: "Destination: Seven deposit addresses on Arbitrum network. Final Destination: KuCoin exchange."
- URL: [Source: https://www.kucoin.com/news/flash/zachxbt-discloses-5-5m-eth-theft-via-tornado-cash-and-cctp-bridge]
Claim: KuCoin has a history of AML deficiencies that facilitate such laundering.
- Evidence snippet: "KuCoin operated as unlicensed money transmitter... Received over $5 billion and sent over $4 billion in suspicious/criminal proceeds... No-KYC policy was integral to its growth."
- URL: [Source: https://bitcoinfoundation.org/news/crimes-and-fraud-news/zachxbt-kucoin/]