Ethereum wallet known as “Drift Exploiter 4” on Etherscan started transferring money associated with the hacking of Drift Protocol, amounting to $285 million in April. According to blockchain security company PeckShield, an address linked with the Drift exploiter sent out about $44.4 million in 23,095.1 ETH to Tornado Cash, with an additional transfer of 0.85 ETH to Bybit.
According to Etherscan transaction records, the wallet is identified as 0xbDdAE987FEe930910fCC5aa403D5688fB440561B and it is seen that the Tornado Cash deposits were segregated into several transactions. The address also belongs to Arkham Intelligence’s “Drift Protocol Exploiter” group which comprises nearly twenty wallets suspected of being involved with the exploit.
These transactions constitute the first significant movement of the stolen funds in the last four months and make another sizeable amount of illegal crypto available on the market. Although investigators have not made a conclusive attribution, multiple blockchain analytics companies have connected the operation with North Korean state-sponsored hackers or infrastructure utilized in prior operations carried out by the DPRK.
Drift, the biggest perpetual futures trading platform on Solana, lost approximately $285 million following a hack where scammers exploited the protocol instead of taking advantage of a loophole in its smart contracts. PeckShield claimed the incident reduced Drift’s total value locked by over 50% and allowed the thieves to quickly transfer most of the stolen funds from Solana to Ethereum before going silent.
The most recent transfers align with the laundering patterns seen by blockchain investigators. Chainalysis’ 2026 Crypto Crime Report suggests that groups with links to North Korea are known to keep stolen assets dormant for many weeks before using bridges, wallets and privacy technology to carry out transfers and make recovery challenging.
Routing the funds through Tornado Cash also follows a familiar playbook. Although the mixer has remained under U.S. sanctions since 2022, investigators say it is still widely used to obscure links between deposits and withdrawals. Even so, firms including Chainalysis and Elliptic say wallet clustering and cross-chain analysis can still help trace portions of those transactions.
The separate 0.85 ETH transfer to Bybit may have been a small test transaction before larger cash-out attempts.
Social engineering—not smart contracts—enabled the $285M theft
Investigators later concluded that the exploit was driven by a months-long social engineering campaign rather than a coding flaw.
According to a Chainalysis report, the attackers spent about six months posing as representatives of a quantitative trading firm, attending industry events, meeting Drift contributors and depositing more than $1 million into the protocol to build trust before compromising developer devices.
The attackers then obtained pre-signed approvals from two of Drift’s five Security Council members by abusing Solana’s durable nonce feature. They also created a low-value token called CarbonVote Token (CVT), inflated its price through wash trading and used it as collateral to increase borrowing limits before draining the protocol in 31 withdrawals over roughly 12 minutes, according to Chainalysis.
This incident had ramifications far outside Drift. Chainalysis reports that no fewer than 20 projects based on Solana saw disruptions in their processes as a result of using the vault structure from Drift as a source of yield. The incident added to the drop in activity on Solana Decentralized Finance projects.
However, despite the latest effort to launder the funds, blockchain analysts are still tracking the stolen crypto. Organizations like Chainalysis, Elliptic, and Merkle Science track illegal transactions by applying wallet clustering, analyzing time gaps, and tracing across different blockchains. It is much harder to recover the stolen funds after the assets have passed through the mixer, but there are cases where the stolen crypto was either returned or frozen by the blockchain analysts.
The latest transactions made to Tornado Cash indicate that the Drift exploit has resumed its activity in the laundering process.
The smartest crypto minds already read our newsletter. Want in? Join them.