Cryptocurrency thieves 'money laundering strategy upgrades
In the Aztec Connect rollover vulnerability, a hacker demonstrated a new method of money laundering through a series of coordinated fund transfers. The hacker had previously deposited 300 ETH into Tornado Cash and recently transferred a total of 500 ETH. This operation suggests a deliberate strategy to cover up stolen assets from decentralized financial agreements.
What does abnormal transfer imply?
Unlike previous operations of moving funds quickly, the hacker adopted a more orderly approach rather than pursuing speed. On August 8, PeckShield tracked a significant transfer of 300 ETH (approximately $572,100), marking its continued injection of funds into Tornado Cash. Earlier on July 2, a transaction of 145 ETH (approximately US$227.65 million) was also identified, totaling 200 ETH before recent operations.
These activities took place more than a month apart, reflecting the hacker's intention to decentralize the transfer process of the 909 ETH pieces he stole. Currently, the attacker has transferred more than half of the stolen funds through a series of small transfers.
"The slow transfer of funds through Tornado Cash is in sharp contrast to cases such as the 2022 Beanstalk incident. In that incident, the attacker executed 270 transactions involving 24,930 ETH in minutes, taking advantage of the anonymity of the currency mixer but relying on speed."
Aztec investigators pointed out that although currency mixers such as Tornado Cash provide anonymity, trading behavior and time patterns can still reveal clues. Through advanced analytics and monitoring of blockchain-related activities, the path of funds can still be traced even if they pass through anonymous networks.
Where did the Aztec vulnerability come from?
The incident originated from a vulnerability in the Aztec Connect rollover contract, which was used by hackers on June 14 to steal approximately US$2.19 million, including 909 ETH and various other cryptocurrencies. Subsequently, the attacker used similar tactics to target older protocol components and stole an additional $88,000.
Blockaid's investigation concluded that the attack originated from a flaw in the verification and settlement logic, rather than a breach of the encryption technology itself. Although the target contract has been scrapped, the current Aztec network and its native tokens have not been affected.
The number of blockchain-related hacking incidents is rising, with 207 incidents recorded in the first half of 2026. Globally, Tornado Cash is involved in laundering 20% of these illicit funds. Despite the sanctions, Tornado Cash remains the preferred currency mixing channel for 78.33% of funds in Ethereum-related thefts. U.S. legal changes have reshaped the operating environment for mixed-currency services.
The Aztec theft case shows that legacy smart contract contracts pose significant risks. Although the total damage caused by hacking has declined, the number of incidents has increased, highlighting the urgency of strengthening protection measures. Facilities that provide real-time data and analysis can provide critical assistance to stakeholders who want to respond to potential threats ahead of time.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH