Logo
My Crypto News AI

After Four Months of Silence, $285M Drift Hacker Moves Stolen Funds Again

A wallet linked to one of crypto's largest heists has suddenly sprung back to life. On July 24, 2026, blockchain security firm PeckShield detected that the address responsible for the $285 million Drift Protocol hack moved $44.4 million in Ethereum (ETH) to Tornado Cash, a privacy mixer, marking the first significant movement of the stolen funds in four months. The activity suggests the attacker is resuming efforts to launder and cash out the proceeds from what investigators now believe was driven by social engineering, not a smart contract flaw.

What Happened in the Original Drift Protocol Hack?

Drift Protocol, the largest perpetual futures trading platform on Solana, suffered a devastating breach in April 2026 that drained approximately $285 million from the protocol. Unlike many high-profile crypto exploits that result from code vulnerabilities, investigators later determined that this attack was orchestrated through a months-long social engineering campaign. The attackers posed as representatives of a quantitative trading firm, attended industry events, built relationships with Drift contributors, and deposited over $1 million into the protocol to establish credibility before compromising developer devices.

Once they gained access to compromised devices, the attackers exploited Solana's durable nonce feature to obtain pre-signed approvals from two of Drift's five Security Council members. They then created a fake token called CarbonVote Token (CVT), artificially inflated its price through wash trading, and used it as collateral to increase their borrowing limits. Within roughly 12 minutes, they executed 31 withdrawals that emptied the protocol. The hack had ripple effects across Solana's decentralized finance (DeFi) ecosystem; Chainalysis reported that at least 20 Solana-based projects experienced disruptions because they relied on Drift's vault structure as a source of yield.

How Are Investigators Tracking the Stolen Funds?

The recent movement of funds provides a window into how sophisticated crypto theft laundering operates. The wallet identified as "Drift Exploiter 4" on Etherscan, with the address 0xbDdAE987FEe930910fCC5aa403D5688fB440561B, transferred 23,095.1 ETH worth approximately $44.4 million to Tornado Cash in multiple segregated transactions. The same wallet also sent 0.85 ETH to the cryptocurrency exchange Bybit, which analysts believe may have been a small test transaction to probe cash-out routes before larger withdrawal attempts.

Blockchain analytics firms including Chainalysis, Elliptic, and Merkle Science continue to monitor the stolen crypto using wallet clustering, time-gap analysis, and cross-chain tracing techniques. Although Tornado Cash has been under U.S. sanctions since 2022, it remains widely used to obscure the connection between deposits and withdrawals. However, investigators say that even after funds pass through privacy mixers, advanced forensic techniques can still trace portions of those transactions. The pattern of activity aligns with known laundering tactics used by North Korean state-sponsored hacking groups, which typically keep stolen assets dormant for extended periods before attempting to move them through bridges, privacy tools, and other obfuscation methods.

Steps Blockchain Analysts Use to Track Stolen Crypto

  • Wallet Clustering: Analysts group related addresses together to identify patterns and connections between seemingly separate accounts controlled by the same entity.
  • Cross-Chain Analysis: Investigators trace fund movements across multiple blockchains, such as from Solana to Ethereum, to follow the complete path of stolen assets.
  • Time-Gap Monitoring: Experts analyze the timing and intervals between transactions to identify behavioral patterns and predict future movement attempts.
  • Privacy Mixer Forensics: Even after funds enter mixers like Tornado Cash, advanced techniques can correlate deposit and withdrawal patterns to recover portions of transaction history.

Who Is Behind the Attack?

Multiple blockchain intelligence firms have attributed the Drift exploit to UNC4736, a North Korean state-affiliated hacking group also tracked under the name AppleJeus. Nexus Mutual reports that this is believed to be the same crew responsible for the 2024 Radiant Capital hack. The attribution is based on the operational patterns observed in the attack, including the months-long social engineering campaign, the use of Solana-specific technical features, and the post-exploit laundering methodology that mirrors previous North Korean-linked operations.

The timing of the recent fund movements is significant. Chainalysis's 2026 Crypto Crime Report notes that groups with North Korean connections are known to keep stolen assets dormant for many weeks before attempting to move them, a strategy designed to reduce the likelihood of detection and allow regulatory attention to fade. The four-month silence followed by sudden activity suggests the attackers may believe the window for safe movement has opened, or they face pressure to convert the stolen funds into fiat currency or other assets.

What Does This Mean for the Broader Crypto Industry?

The Drift hack and the ongoing laundering attempts underscore a persistent vulnerability in the crypto ecosystem: social engineering and operational security failures can be just as damaging as smart contract bugs. While developers invest heavily in code audits and formal verification, attackers are increasingly targeting the human element, compromising the devices and credentials of key personnel rather than exploiting protocol logic.

The fact that investigators can still track the stolen funds, even as they move through privacy mixers and across blockchains, offers some hope for recovery. However, the longer the funds remain in circulation, the harder recovery becomes. Blockchain analysts will continue monitoring the addresses associated with the Drift exploit, but the attacker's demonstrated sophistication and apparent state-level backing suggest they have resources and expertise to eventually move the funds in ways that are difficult to trace.

For users and protocols in the Solana ecosystem and beyond, the Drift incident serves as a reminder that security extends far beyond code; it requires robust operational practices, multi-factor authentication, device security, and careful vetting of individuals with access to critical infrastructure.