The wallet cluster tied to the Drift Protocol exploit has come back to life. On July 23, on-chain sleuths flagged a fresh round of laundering activity from the address labelled “Drift Exploiter 4,” moving tens of millions of dollars worth of Ether into the sanctioned privacy mixer Tornado Cash after nearly a full quarter of silence.
Blockchain intelligence account Lookonchain confirmed the movement in a post today, noting that the exploiter had deposited 23,095 ETH, worth roughly $44.4 million at current prices, into Tornado Cash in a single burst.
According to Arkham Intelligence data attached to the post, the same entity still controls 107,165 ETH, valued at approximately $201 million, along with smaller balances in USDT, USDC, and other stablecoins.
Security firm PeckShieldAlert independently corroborated the transfers in a separate post, adding that 0.85 ETH was also sent to a deposit address associated with the Bybit exchange, a smaller test-like transfer that often precedes larger off-ramp attempts.
How The Money Moved
The transaction pattern seen on Etherscan is textbook mixer behaviour. Between roughly 08:20 UTC and 09:06 UTC on July 23, the Drift Exploiter 4 address executed dozens of back-to-back deposits into the Tornado Cash router, structured in tranches of 1 ETH, 10 ETH and 100 ETH. Several deposits went out multiple times per minute, a rhythm consistent with an automated script rather than manual signing.
Interspersed with the mixer deposits were three smaller outgoing transfers of 0.16 ETH, 0.35 ETH and 0.1 ETH, sent to fresh addresses. On-chain analysts believe these are peel-off wallets meant to test exchange deposit routes before the exploiter commits larger volumes.
Data from Onchain Lens, cited by BlockBeats, described these as the exploiter’s first transfers in three months, breaking a dormancy that had stretched since late April.
Where It All Started
Drift Protocol, the largest decentralised perpetual futures exchange on Solana, was drained of approximately $285 million on April 1, 2026, in what became the largest DeFi exploit of the year. The attack lasted around 12 minutes and was executed not through a smart contract bug but through a combination of social engineering, compromised multisig signers, and abuse of Solana’s durable nonce feature.
The attacker manufactured a fake token called CarbonVote (CVT), seeded it with a few thousand dollars of liquidity on Raydium, and used wash trading to fabricate a $1 price history that Drift’s oracle then accepted. With CVT whitelisted as collateral, the exploiter deposited hundreds of millions in worthless tokens and drained real USDC, JLP and SOL-denominated assets in 31 pre-signed transactions.
TRM Labs, Elliptic and Chainalysis have all attributed the incident with medium-high confidence to North Korean state-affiliated group UNC4736, also tracked as AppleJeus and Citrine Sleet, the same cluster tied to the $1.5 billion Bybit heist of February 2025 and the $50 million Radiant Capital breach in October 2024.
Fallout Still Widening
The Drift hack triggered a wave of collateral damage across the Solana DeFi ecosystem. The protocol’s total value locked collapsed from around $550 million pre-hack to under $250 million within a day, and the DRIFT token remains roughly 98 percent below its all-time high.
Yield-linked platforms exposed to Drift’s vaults began falling one by one. Carrot Protocol shut down in early May after losing more than half its TVL, and Solana-based crypto card issuer Pyra terminated its card services in June, citing unrecoverable Drift exposure.
On the recovery side, Tether stepped in with a $147.5 million relaunch package that included a $100 million revenue-linked credit line, an ecosystem grant and market maker loans. At the same time, Drift onboarded Asymmetric Research and OtterSec to lead a coordinated recovery effort.
Circle, meanwhile, faced heavy criticism from on-chain investigator ZachXBT for failing to freeze more than $230 million in stolen USDC that was bridged from Solana to Ethereum via its own CCTP during the six-hour window after the hack began. That controversy escalated into a broader debate on stablecoin freeze powers and a federal lawsuit.
What Comes Next
With today’s fresh Tornado Cash deposits, only around $44.4 million of the exploiter’s estimated $245 million ETH stash has entered the mixer so far. The bulk, 107,165 ETH, remains parked in identified wallets that Etherscan and Arkham continue to flag as Drift Exploiter addresses.
If the current pace holds, with tranches of 100 ETH being fired into the router multiple times per minute, the remaining balance could be washed through Tornado Cash within days rather than weeks. On-chain teams at TRM Labs, Elliptic and SEAL 911 are actively tracing the outflows, and centralised exchanges have been alerted to watch for deposits matching the peel-off wallet fingerprints.
For now, the resumption of activity signals that the group behind one of 2026’s most consequential DeFi thefts is confident enough to move again, and that the recovery window for the stolen funds is narrowing fast.
Also Read: Verus Ethereum Bridge Exploited Again for $7.54M in Repeat Attack
