
A wallet tied to the $285 million Drift Protocol exploit moved 23,095.1 Ether, worth about $44.4 million, into Tornado Cash after roughly three months of inactivity.
Summary
- Drift’s exploiter deposited 23,095 ETH into Tornado Cash after remaining inactive for three months.
- ZachXBT declined further tracking, citing resources required to monitor and freeze a nine-figure DPRK theft.
- Drift previously announced a recovery bounty program with Arkham and Bybit, contrary to online claims.
The same address sent 0.85 ETH to wallets labeled as Bybit deposit addresses, according to Etherscan records and monitoring attributed to PeckShield.
Transfers began on July 23 and continued into July 24, on-chain records show. Researcher JL, known as 0xJaelle, flagged the movement and tagged ZachXBT. The investigator replied that he did not plan to keep following the funds without institutional support.
Drift exploiter empties an Ethereum wallet
The Etherscan address labeled “Drift Exploiter 4” processed hundreds of transactions during the movement. Records show repeated deposits of 100 ETH, 10 ETH and 1 ETH into the Tornado Cash router. Four other transfers totaling 0.85 ETH went to addresses labeled as Bybit deposits.
Onchain Lens first reported that the attacker had resumed activity and was sending 100 ETH batches into the mixer several times per minute. The wallet had remained largely inactive since the April attack.
Tornado Cash pools deposits and permits later withdrawals through different addresses. That can weaken the direct public link between sending and receiving wallets. Investigators may still use timing, transaction patterns and exchange activity, but the process requires more data and staff.
The movement covers only part of the original theft. Drift’s April recovery update valued stolen assets at $295.7 million across JLP, USDC, Bitcoin-linked tokens, SOL, WETH and other assets. The protocol said much of the converted value remained across four flagged Ethereum wallets.
ZachXBT cites cost of tracking North Korea-linked funds
ZachXBT wrote, “Sorry I currently do not have any plans to track these funds further.” He said monitoring a nine-figure North Korea-linked exploit and working toward possible freezes would require resources beyond one independent investigator.
He described the task as “difficult for a team and not feasible for a single person.” ZachXBT also said Drift was not a donor or client. His response on X drew attention to the cost of investigations that continue for months.
The comments do not show that no organization is watching the wallets. Drift has said it works with law enforcement, Mandiant and blockchain intelligence firms. Etherscan continues to label the address, while exchanges can review deposits connected to flagged wallets.
Elsewhere, ZachXBT criticized Circle after about $232 million in stolen USDC crossed from Solana to Ethereum during the April attack. The funds moved through Circle’s cross-chain system before the attacker converted much of the value into ETH.
Drift had announced a recovery bounty program
JL later said it was surprising that Drift had not created a recovery bounty. Drift’s public record shows that it had announced plans for one. On April 16, the protocol said it was developing a bounty program with support from Arkham and Bybit.
However, the update did not provide a final reward amount, eligibility rules or payment schedule. It remains unclear whether the program became fully active, whether it covered continuing wallet monitoring, or whether independent researchers could claim payment for later tracing work.
Drift also created a user recovery plan separate from stolen-fund tracking. Tether proposed up to $127.5 million in support. Drift plans to issue recovery tokens and fund redemptions through remaining assets, partner capital and future exchange revenue.
The protocol’s June investigation update said Mandiant attributed the attack to UNC6862, a North Korean threat group. Drift said the attackers used social engineering and compromised operational access rather than a smart contract flaw. As crypto.news reported, the attackers emptied key vaults within about 12 minutes.
Recovery continues as the trail becomes harder to follow
Drift has focused on rebuilding its platform and funding user claims while forensic teams pursue the stolen assets. Its recovery framework states that recovered funds will enter the user recovery pool. The protocol also plans stronger signing controls for critical transactions.
The April attack affected other Solana projects. As previously reported, yield platform Carrot decided to shut down after losses linked to Drift erased most of its deposited value.
The Tornado Cash deposits do not prove that the attacker converted the ETH into usable cash. The deposits remain public, and investigators may still identify later withdrawals. However, they remove a simple wallet-to-wallet trail and make the next phase harder.
Neither Drift nor Solana had publicly responded to ZachXBT’s comments at the time of writing. Bybit had not announced whether it reviewed the small deposits shown on Etherscan. The remaining stolen funds and the status of Drift’s planned bounty program remain unresolved.
