A wallet linked to April’s $285 million Drift Protocol exploit has resumed activity, moving 23,095 ETH, worth roughly $44.4 million, into Tornado Cash on July 23 and 24 after nearly three months of dormancy.
According to on-chain data from Etherscan, the wallet also sent small test transactions totaling 0.85 ETH to addresses labeled as Bybit deposit wallets, while blockchain security firms continue to monitor the remaining stolen assets.
The renewed movement comes as Drift Protocol continues its recovery efforts with law enforcement and blockchain intelligence partners.
Exploit wallet resumes activity with Tornado Cash transfers
Blockchain monitoring platform Onchain Lens first reported the renewed activity after detecting repeated transfers of 100 ETH, alongside smaller 10 ETH and 1 ETH deposits, into Tornado Cash over several hours.
Security researcher JL (0xJaelle) flagged the transactions on X, drawing attention to the wallet’s return after months of inactivity and tagging renowned blockchain investigator ZachXBT for additional analysis.
Tornado Cash is designed to enhance transaction privacy by pooling cryptocurrency deposits before allowing withdrawals to unrelated addresses.
While the protocol does not automatically conceal criminal proceeds, it significantly complicates blockchain tracing by weakening the direct transaction link between sender and recipient.
Despite the latest transfers, the laundered funds account for only a portion of the assets stolen during the April exploit.
Drift’s latest recovery update estimated total losses at $295.7 million, spanning ETH, USDC, Solana (SOL), Bitcoin-linked assets, JLP, and other cryptocurrencies, with a substantial share still believed to reside across several monitored Ethereum wallets.
Investigators highlight the growing cost of blockchain forensics
The renewed fund movements also reignited discussion about the increasing burden placed on independent blockchain investigators.
Responding publicly on X, ZachXBT said he would not continue tracking the wallets without institutional backing.
“Sorry I currently do not have any plans to track these funds further.” — ZachXBT, blockchain investigator.

He explained that monitoring a nine-figure exploit allegedly linked to North Korean threat actors requires significant resources beyond what an independent researcher can reasonably provide.
His remarks sparked broader conversations within the crypto community about the need for sustainable funding models for blockchain investigations.
Although ZachXBT stepped back from independently following the funds, Drift has previously confirmed that it continues working alongside law enforcement, Google-owned Mandiant, and blockchain intelligence firms to pursue asset recovery.
Exchanges can also review deposits originating from wallets already flagged by blockchain analytics platforms.
Questions remain over Drift’s recovery bounty
The renewed laundering activity has also revived scrutiny over Drift Protocol’s proposed recovery bounty program.
Following the April exploit, Drift announced plans to launch a recovery initiative in partnership with Arkham Intelligence and Bybit, encouraging researchers to assist in tracing stolen funds.
However, while the protocol confirmed the program’s development, it has yet to publicly disclose final reward amounts, eligibility criteria, or payout structures, leaving uncertainty over whether independent investigators can claim compensation for continued tracking efforts.
Separately, Drift has introduced a broader user recovery framework supported by Tether, which proposed up to $127.5 million in assistance.
The protocol plans to compensate affected users through recovery tokens, remaining treasury assets, strategic funding, and future exchange revenues.
According to Drift’s June investigation update, cybersecurity firm Mandiant attributed the attack to UNC6862, a North Korean cyber threat group known for targeting cryptocurrency infrastructure through social engineering rather than exploiting smart contract vulnerabilities.
“The attackers used social engineering and compromised operational access rather than a smart contract flaw.” — Drift Protocol, June investigation update.

Recovery efforts continue as laundering complicates investigations
The latest wallet activity illustrates a familiar reality in digital asset security: blockchain transactions remain permanently visible, but tracing stolen funds becomes considerably more difficult once they pass through privacy-enhancing services such as Tornado Cash.
The latest deposits do not confirm that the attacker has successfully converted the Ether into fiat currency or otherwise realized the stolen value.
Instead, they represent another stage in an ongoing laundering process that investigators may still analyze through transaction timing, withdrawal patterns, exchange cooperation, and blockchain intelligence techniques.
Meanwhile, Drift continues strengthening its operational security by implementing stricter transaction-signing controls while pursuing asset recovery.
The protocol has stated that any recovered funds will be directed toward compensating affected users.
At the time of publication, neither Drift Protocol nor Solana had publicly responded to ZachXBT’s recent comments regarding the investigation.
Bybit has also not announced whether it has reviewed the small deposits linked to addresses labeled on Etherscan.
As one of the largest crypto security incidents of 2026 continues to unfold, investors will be closely watching whether investigators can recover additional assets or whether the latest Tornado Cash transactions mark another setback in tracing the stolen funds.