Fund Movement Methodology
Published 7/24/2026, 10:43:51 AM
The Drift Protocol exploiter, widely attributed to the North Korean state-sponsored Lazarus Group (UNC4736/UNC6862), resumed laundering stolen funds through Tornado Cash on July 23–24, 2026, following a three-month period of dormancy. After the initial $285 million exploit on April 1, 2026, the attacker has recently funneled approximately 23,095.1 ETH (~$44.4 million) into the mixer to obfuscate the trail of the stolen assets [Source: https://phemex.com/en/blog/details/drift-protocol-exploiter-resumes-fund-movement-via-tornado-cash].
Fund Movement Methodology
The laundering process involves a sophisticated cross-chain pipeline designed to break deterministic links between the Solana-based exploit and Ethereum-based exit points:
- Initial Consolidation (Solana): Stolen assets including USDC, SOL, JLP, and WBTC were converted to USDC via Solana DEX aggregators immediately following the hack.
- Cross-Chain Bridging: The attacker moved a significant portion of the funds—estimated between $232 million and $270.9 million—from Solana to Ethereum using Circle’s Cross-Chain Transfer Protocol (CCTP) [Source: https://phemex.com/en/blog/details/drift-protocol-exploiter-resumes-fund-movement-via-tornado-cash].
- Asset Conversion (Ethereum): The bridged USDC was swapped for approximately 129,000 ETH and distributed across multiple "Drift Exploiter" wallets, primarily "Drift Exploiter 4."
- Tornado Cash Injection:
- Batching: Funds are deposited into the Tornado Cash router in rapid-fire batches of 100 ETH. While some reports suggest smaller batches of 10 ETH and 1 ETH, the 100 ETH transfers are the most frequently documented [Source: https://cryptonomist.ch/en/2026/07/drift-protocol-hack-tornado-cash].
- Frequency: During the July 2026 activity, the attacker executed multiple 100 ETH transfers per minute to maximize throughput [Source: https://phemex.com/en/blog/details/drift-protocol-exploiter-resumes-fund-movement-via-tornado-cash].
Laundering Metrics (July 2026 Activity)
| Metric | Detail |
|---|---|
| Total ETH Laundered (July 23-24) | 23,095.1 ETH (~$44.4M) |
| Primary Asset | Ethereum (ETH) |
| Primary Mixing Tool | Tornado Cash |
| Dormancy Period | ~3 months (April 2026 – July 2026) |
| Pre-Exploit Funding | 10 ETH withdrawn from Tornado Cash on March 11, 2026, for infrastructure |
Strategic Use of Tornado Cash
The attacker utilizes the mixer at two distinct stages:
- Infrastructure Funding: On March 11, 2026, the attacker withdrew 10 ETH from Tornado Cash to fund the deployment of a fake "CarbonVote Token" (CVT) used in the social engineering phase of the attack [Source: https://cryptonomist.ch/en/2026/07/drift-protocol-hack-tornado-cash].
- Post-Exploit Obfuscation: By pooling deposits with other users and withdrawing to fresh addresses, the attacker breaks the on-chain link. This forces investigators to rely on probabilistic timing analysis rather than direct transaction tracing.
Current Status
As of July 24, 2026, the laundering activity is ongoing. While blockchain security firms like Elliptic and TRM Labs are monitoring the movement, the sheer volume and speed of the transfers make real-time intervention difficult. There has been notable public criticism regarding the speed of asset freezes during the initial bridging phase, particularly concerning the use of Circle's CCTP [Source: https://phemex.com/en/blog/details/drift-protocol-exploiter-resumes-fund-movement-via-tornado-cash].