EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

After months of silence,$285 million Drift hackers are moving money again

2026-07-26 00:38:11
Bookmark

After several months of silence, Drift's stolen funds are flowing again.

The Ethereum wallet marked as "Drift Exploiter 4" by Etherscan has recently begun to transfer funds related to Drift Protocol hacking attacks. The attack occurred in April this year and involved approximately $285 million. According to monitoring by blockchain security company PeckShield, an address associated with Drift hackers has sent approximately 23,095.1 ETH (worth approximately $44.4 million) to Tornado Cash, and an additional 0.85 ETH has been transferred to Bybit.

According to Etherscan's transaction records, the wallet address is 0xbDdAE987FEe 930910fCC5aa 403D5688fB 440561B, and its deposits to Tornado Cash are split into multiple transactions. The address was also included by Arkham Intelligence in the "Drift Protocol Exploiter" group, which contains nearly 20 wallets suspected of participating in the attack.

These transactions are the first large-scale flow of stolen funds in the past four months, meaning another significant amount of illegal cryptocurrency has entered the market. Although investigators have not yet made a firm explanation, multiple blockchain analysis companies have linked the operation to North Korea's state-backed hacking groups or related infrastructure used by North Korea in previous operations.

Drift funds resume flowing after months of silence

Drift, the largest perpetual contract trading platform on Solana, lost approximately US$285 million due to hacking attacks. Rather than exploiting the smart contract vulnerability, the attacker directly invades the protocol itself. PeckShield said the incident caused Drift's total lockups to drop by more than 50%, and the attackers quickly moved most of the stolen funds from Solana to Ethereum, before disappearing.

The latest transfer model is consistent with money laundering methods previously observed by blockchain investigators. The "2026 Cryptocurrency Crime Report" released by Chainalysis pointed out that gangs associated with North Korea often idle stolen assets for weeks and then transfer them through cross-chain bridges, wallets and privacy technologies, making the recovery work difficult.

Transfer of funds through Tornado Cash is also a common method. Although the currency mixer has been subject to U.S. sanctions since 2022, investigators say it is still widely used to blur the connection between deposits and withdrawals. Even so, companies such as Chainalysis and Elliptic point out that these transactions can still be partially traced through wallet clustering analysis and cross-chain tracking.

The 0.85 ETH transfer to Bybit may be a small test transaction in preparation for subsequent larger-scale cash-out.

Social engineering attack-not smart contract vulnerability-led to the theft of $285 million

Investigators later concluded that the attack was not caused by a code breach, but rather originated from a social engineering attack that lasted for months. Chainalysis reported that the attacker pretended to be a representative of a quantitative trading company, spent approximately six months attending industry events, meeting with Drift team members, and depositing more than $1 million into the agreement to build trust before hacking into developer equipment.

Chainalysis pointed out that the attacker used Solana's persistent nonce feature to obtain pre-signed authorizations from two of Drift's five Security Council members. They also created a low-value token called CarbonVote Token (CVT), raised its price through a swipe transaction and used it as collateral to increase borrowing limits, and then cleared the agreement with 31 withdrawals in about 12 minutes.

Blockchain detectives are still tracking Drift's stolen cryptocurrency

The impact of this incident goes far beyond Drift itself. Chainalysis reported that at least 20 Solana-based projects experienced process interruptions due to the use of Drift's vault structure as a source of revenue. The incident further exacerbated the decline in activity in Solana's decentralized financial projects.

Despite recent money laundering actions, blockchain analysts are still tracking stolen cryptocurrencies. Organizations such as Chainalysis, Elliptic and Merkle Science continue to monitor illegal transactions through wallet clustering analysis, time interval analysis, and cross-chain tracking. Once assets pass through the currency mixer, recovery becomes much more difficult, but there are still cases where stolen cryptocurrencies are recovered or frozen by blockchain analysts.

The latest transaction to Tornado Cash indicates that money laundering related to the Drift attack has been restarted.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP