EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Aztec attacker transfers 500 ETH to Tornado Cash, in record year for hacking

2026-08-09 00:26:06
Bookmark

The hackers transferred another 300 ETH to Tornado Cash, bringing the total to 500 ETH

According to monitoring by blockchain security company PeckShield, the hackers who attacked Aztec's abandoned Connect rollup in June this year recently transferred another 300 ETH to Tornado Cash, bringing the total amount received by the currency mixer to 500 ETH.

The key to this transfer is not only the amount, but also the speed. Hackers have transferred about 55% of the originally stolen 909 ETH through Tornado Cash, but not in one go, but in batches with variable amounts. This regular pace suggests that its exit strategy does not launder money as quickly as other large cryptocurrency attacks.

Slow-penetration currency mixer

PeckShield reported that the latest 300 ETH (worth approximately US$572,100 at the time) was deposited into Tornado Cash on August 8. A month ago, on July 2, the agency marked a deposit of 145 ETH (approximately US$227.65 million), bringing the cumulative amount to 200 ETH.

The time point revealed a lot of information. The hacker did not transfer all the stolen ETH at once, but transferred small amounts into the currency mixer in batches. The most recent deposit was 37 days apart from the previous transaction.

This is in sharp contrast to the Beanstalk incident in 2022. According to Merkle Science analysis, criminals made 270 transfers through Tornado Cash, totaling 24,930 ETH, and most of the transfers were similar in amounts, with intervals of only a few seconds.

The slow operation of Aztec hackers did not allow funds to be completely hidden. Tornado Cash is designed to cut off the chain between deposits and withdrawals, but transaction times, wallet behavior, and operations outside of the money mixer can still reveal information. According to TRM Labs, the company successfully tracked the funds hidden by the currency mixer through behavioral and time correlation analysis, anonymous set identification, and export channel positioning.

The origin of 500 ETH

The stolen funds date back to June 14, when a cybercriminal stole approximately $2.19 million from the abandoned Aztec Connect roll-up contract through a transfer. According to Blockaid, the stolen assets included 909 ETH, 270,513 DAI, 168 wstETH and other tokens.

Just one day later, the same legacy system was attacked again and approximately $88,000 in remaining assets were stolen. Blockaid said the hackers used the same settlement method for the remaining bridged positions.

The most important finding of this attack is that it did not break Aztec's underlying encryption technology. Instead, Blockaid found flaws in the verification and settlement boundary process that allowed hackers to generate balances out of thin air without deposit support.

Aztec Connect has previously been deprecated, and Aztec Labs no longer holds management keys for affected unchangeable contracts. Current Aztec network and AZTEC tokens are not affected.

Why stolen funds still flow to Tornado Cash

The Aztec case reflects a broader trend in the cryptocurrency space: Although the average value of a single attack is declining, the number of attacks is increasing.

According to TRM Labs data, a total of 207 cryptocurrency hacking incidents occurred in the first half of 2026, setting a record for the same period. The total damage caused by hacking reached $972 million, less than half of the $2.3 billion stolen in the first half of 2025. There will be 125 smart contract vulnerability attacks in 2026, with a median loss of approximately US$219,000.

Tornado Cash remains an important part of the money laundering system. TRM pointed out in its June report that the mixer accounted for only 20% of global mixer activity in 2026, but remains the main mixer in the Ethereum network, although its share has dropped significantly since U.S. sanctions in 2022.

Academic research has also proved the relevance of Tornado Cash. A study by scholars at the University of Birmingham and the University of Sydney found that during the survey period, 78.33% of all hacking incidents on the Ethereum blockchain used Tornado Cash.

The legal environment has changed since then. On March 21, 2025, the U.S. Treasury Department lifted sanctions on Tornado Cash after the Fifth Circuit Court ruled that unchangeable smart contracts were not property within the jurisdiction of the Office of Foreign Assets Control (OFAC).

For investors and DeFi participants, the Aztec incident is a microcosm of a broader problem: Even if the agreement has been scrapped, terminated contracts may still have economic value for a long time. If important funds are locked in outdated technology, this weak link can become a source of loss. Once funds are stolen, the money laundering methods used by criminals are not new.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP