After several months of silence, Drift's stolen funds are flowing again.
The Ethereum wallet marked as "Drift Exploiter 4" by Etherscan has recently begun to transfer funds related to Drift Protocol hacking attacks. The attack occurred in April this year and involved approximately $285 million. According to monitoring by blockchain security company PeckShield, an address associated with Drift hackers has sent approximately 23,095.1 ETH (worth approximately $44.4 million) to Tornado Cash, and an additional 0.85 ETH has been transferred to Bybit.
According to Etherscan's transaction records, the wallet address is 0xbDdAE987FEe 930910fCC5aa 403D5688fB 440561B, and its deposits to Tornado Cash are split into multiple transactions. The address was also included by Arkham Intelligence in the "Drift Protocol Exploiter" group, which contains nearly 20 wallets suspected of participating in the attack.
These transactions are the first large-scale flow of stolen funds in the past four months, meaning another significant amount of illegal cryptocurrency has entered the market. Although investigators have not yet made a firm explanation, multiple blockchain analysis companies have linked the operation to North Korea's state-backed hacking groups or related infrastructure used by North Korea in previous operations.
Drift funds resume flowing after months of silence
Drift, the largest perpetual contract trading platform on Solana, lost approximately US$285 million due to hacking attacks. Rather than exploiting the smart contract vulnerability, the attacker directly invades the protocol itself. PeckShield said the incident caused Drift's total lockups to drop by more than 50%, and the attackers quickly moved most of the stolen funds from Solana to Ethereum, before disappearing.
The latest transfer model is consistent with money laundering methods previously observed by blockchain investigators. The "2026 Cryptocurrency Crime Report" released by Chainalysis pointed out that gangs associated with North Korea often idle stolen assets for weeks and then transfer them through cross-chain bridges, wallets and privacy technologies, making the recovery work difficult.
Transfer of funds through Tornado Cash is also a common method. Although the currency mixer has been subject to U.S. sanctions since 2022, investigators say it is still widely used to blur the connection between deposits and withdrawals. Even so, companies such as Chainalysis and Elliptic point out that these transactions can still be partially traced through wallet clustering analysis and cross-chain tracking.
The 0.85 ETH transfer to Bybit may be a small test transaction in preparation for subsequent larger-scale cash-out.
Social engineering attack-not smart contract vulnerability-led to the theft of $285 million
Investigators later concluded that the attack was not caused by a code breach, but rather originated from a social engineering attack that lasted for months. Chainalysis reported that the attacker pretended to be a representative of a quantitative trading company, spent approximately six months attending industry events, meeting with Drift team members, and depositing more than $1 million into the agreement to build trust before hacking into developer equipment.
Chainalysis pointed out that the attacker used Solana's persistent nonce feature to obtain pre-signed authorizations from two of Drift's five Security Council members. They also created a low-value token called CarbonVote Token (CVT), raised its price through a swipe transaction and used it as collateral to increase borrowing limits, and then cleared the agreement with 31 withdrawals in about 12 minutes.
Blockchain detectives are still tracking Drift's stolen cryptocurrency
The impact of this incident goes far beyond Drift itself. Chainalysis reported that at least 20 Solana-based projects experienced process interruptions due to the use of Drift's vault structure as a source of revenue. The incident further exacerbated the decline in activity in Solana's decentralized financial projects.
Despite recent money laundering actions, blockchain analysts are still tracking stolen cryptocurrencies. Organizations such as Chainalysis, Elliptic and Merkle Science continue to monitor illegal transactions through wallet clustering analysis, time interval analysis, and cross-chain tracking. Once assets pass through the currency mixer, recovery becomes much more difficult, but there are still cases where stolen cryptocurrencies are recovered or frozen by blockchain analysts.
The latest transaction to Tornado Cash indicates that money laundering related to the Drift attack has been restarted.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH