Blockchain monitors flagged significant movement from a wallet tied to the April 2026 Drift Protocol exploit. After nearly three months of inactivity, the address deposited 23,095.1 ETH, valued at about $44.4 million, into Tornado Cash in multiple transactions. The activity, which also included small transfers to Bybit deposit addresses, was publicly noted by PeckShieldAlert.
#PeckShieldAlert The #Drift Exploiter-labeled address has deposited 23,095.1 ETH (~$44.4M) into #TornadoCash and 0.85 $ETH into #Bybit.
Drift suffered an exploit on April 1, 2026, resulting in a loss of ~$285M worth of cryptos. pic.twitter.com/OYuy7EUm6P
— PeckShieldAlert (@PeckShieldAlert) July 24, 2026
- The Drift exploiter moved 23,095.1 ETH, valued at approximately $44.4 million at the time, into Tornado Cash.
- The associated wallet showed no major activity for nearly three months following the April exploit.
- Funds were deposited in batches, including multiple 100 ETH, 10 ETH, and 1 ETH transfers to the Tornado Cash router.
- Small ETH amounts totaling 0.85 ETH were sent to addresses labeled as Bybit deposits.
- Independent investigator ZachXBT stated he has no current plans to track the funds further without institutional backing.
- Drift has implemented a recovery framework featuring a dedicated pool supported by partners including Tether, a recovery token mechanism, and a bounty program.
What Happened
On July 23-24, 2026, the Ethereum address 0xbddae987fee930910fcc5aa403d5688fb440561b, publicly labeled on Etherscan in connection with the Drift exploit, initiated a series of outbound transfers. The wallet, dormant since the April breach, deposited the bulk of its visible ETH holdings into Tornado Cash. The funds were previously transferred from Solana to Ethereum before the latest Tornado Cash activity

Etherscan records show the address executed numerous deposit transactions to the Tornado Cash router, primarily in batches of 100 ETH, 10 ETH, and 1 ETH. Small transfers totaling 0.85 ETH went to Bybit-labeled deposit addresses. The pattern indicates coordinated movement of funds accumulated from the earlier exploit.
Timeline of Events
- April 1, 2026: Drift Protocol suffered a governance compromise resulting in approximately $285–295 million drained.
- April 16, 2026: Drift published its initial recovery update outlining the framework.
- June 3–4, 2026: Update detailed Mandiant attribution and ongoing recovery efforts.
- July 23–24, 2026: Dormant exploiter wallet activated and moved 23,095 ETH into Tornado Cash.
The exact reason for the wallet’s reactivation remains unknown. The movement follows nearly three months of dormancy after the April exploit. No official statements from the wallet operator have been identified.
Recovery Progress Since the Drift Hack
Drift established a recovery pool supported by Tether contributions of up to $127.5 million and other partners. The framework includes issuance of a dedicated recovery token representing claims on the pool. The protocol also launched a bounty program with Arkham and Bybit. Security upgrades encompass new multisig controls, independent audits, and disabled durable nonces for administrative actions. Additional context on the funding shift and exploit scale is available in our coverage.
Official Investigation
Mandiant attributed the April breach to UNC6862, a North Korean threat group, identifying it as a social engineering and operational compromise rather than a smart contract vulnerability. Our previous reporting covers the North Korea-linked aspects of the drain in detail. Drift continues working with law enforcement and forensics partners. ZachXBT declined further independent tracking, citing the resource demands of monitoring a nine-figure DPRK-linked operation.
The movement of $44 million in ETH into Tornado Cash by the Drift exploiter highlights the challenges of tracing funds from the April hack. While the action obscures trails, on-chain records persist for coordinated investigations. Drift’s recovery efforts, including the supported pool, bounty program, and security reforms, continue to address user impacts as forensic work proceeds.
















