Crypto NewsSecurity

North Korea's Drift hackers just moved $44m into Tornado Cash

The North Korea-linked wallet that drained Drift Protocol of about $285 million in April moved $44.4 million into Tornado Cash on 23 July. Here is the on-chain trail, the attribution and why the money is unlikely to come back.

Listen to this article

--:--
Editorial collage: the Drift Protocol logo, a North Korean flag in halftone, Ethereum coins feeding into a Tornado Cash funnel, and an explorer readout of the Drift Exploiter 4 wallet moving 23,095 ETH.

On 23 July 2026 the wallet that drained Drift Protocol of roughly $285 million in April began laundering the money. Between about 08:20 and 09:06 UTC it sent 23,095 ether, about $44.4 million, into Tornado Cash, the Ethereum service that mixes deposits to break the link between where a coin comes from and where it ends up. It was the wallet’s first activity in three months. Every deposit is recorded on Ethereum, so the trail up to the mixer is public.

YFarmX on-chain trace of the Drift Exploiter 4 wallet: 0xbDdA…561B moving 23,095 ETH into the Tornado Cash router 0xd90e…F31b on 23 July 2026 in 1, 10 and 100 ether batches, roughly $44.4 million, with about 107,165 ETH still held.

What moved

The sending address is 0xbDdAE987FEe930910fCC5aa403D5688fB440561B, tagged “Drift Exploiter 4” on Etherscan. The destination is the Tornado Cash router, 0xd90e2f925DA726b50C4Ed8D0Fb90Ad053324F31b.

The 23,095 ether went in as a stream of fixed-size deposits, in denominations of 1, 10 and 100 ether, several a minute, from about 08:20 to 09:06 UTC and continuing into the next day. Tornado Cash only accepts those set amounts, and the pace and regularity point to an automated script rather than transactions signed by hand. At the ether price on 23 July, about $1,920, the total came to roughly $44.4 million.

That is a fraction of what the wallet holds. The same cluster still controls around 107,165 ether, about $201 million, which remains on-chain and flagged.

How the heist worked

The April theft did not exploit a bug in Drift’s code. According to a post-mortem by the forensics firm Chainalysis, the attackers posed as a quantitative trading firm and spent months building trust with people who ran the protocol. They then used a Solana feature called durable nonces, which keeps a signed transaction valid indefinitely instead of expiring within seconds, to get members of Drift’s Security Council to pre-sign transactions they did not fully understand. Broadcast on 1 April, those transactions handed the attacker admin control. Because the signatures were valid, Chainalysis notes, Drift’s normal defences did not flag them.

The attacker then whitelisted a worthless token they had created, pushed its price to about a dollar through wash trading, deposited it as collateral, and borrowed the protocol’s real assets against it. The drain took about twelve minutes. Drift’s own accounting put the loss at $295.7 million across 42 tokens, above the $285 million figure usually quoted.

A governance change made it possible. On 27 March, days before the attack, Drift had moved its Security Council to a two-of-five signing threshold with no time delay, removing the window in which the pre-signed transactions might have been caught.

The North Korea trail

Three forensics firms tracing the money, Chainalysis, Elliptic and TRM Labs, and Drift’s own investigation, attribute the heist to North Korea. Elliptic links it to a state-affiliated group it tracks as UNC4736, also known as AppleJeus and Citrine Sleet, and to the same actor Mandiant blamed for the October 2024 Radiant Capital hack.

On-chain evidence supports a planned operation. Elliptic found the attacker’s Ethereum wallet was created about eight days before the exploit and received a small test transfer from a Drift vault beforehand. The stolen assets were swapped into USDC and bridged from Solana to Ethereum through Circle’s Cross-Chain Transfer Protocol, around $232 million of it, over about six hours. The attribution is a shared assessment by four independent teams, not a courtroom finding.

Why the money is unlikely to come back

The on-chain investigator ZachXBT, who specialises in tracing North Korean crypto theft, has set out why recoveries at this scale rarely work.

ZachXBT post: for a large DPRK exploit a single-digit-percentage recovery is considered a positive outcome, and a recovery bounty does not incentivise competent investigators, because after freezing funds a clawback through law enforcement or civil cases takes months or years.

For a large exploit of this kind, he wrote, a single-digit-percentage recovery counts as a positive outcome, and a bounty does not attract capable investigators, because freezing and clawing back funds through law enforcement or civil cases takes months or years, so the effort up front is not worth the low odds.

ZachXBT post: it is unrealistic to expect one person to manage a large DPRK exploit alone; getting funds frozen depends on law enforcement, timing and jurisdiction, it needs a full team at high cost, and real progress would require collaboration across ecosystems and changes to international law.

He added that it is unrealistic to expect one person to handle a large exploit alone. Getting funds frozen depends on law enforcement, timing and jurisdiction; it needs a full team at high cost, and real progress would require coordination across the industry and changes to international law.

Drift has not made its users whole. Its recovery plan, published on 16 April, relied on outside support: the stablecoin issuer Tether offered up to $127.5 million and other partners up to a further $20 million, against the $295.7 million lost. Affected users received a transferable recovery token, a claim on a pool funded partly by a share of Drift’s future revenue.

Trace it yourself

On etherscan.io, search the wallet 0xbDdAE987FEe930910fCC5aa403D5688fB440561B: the “Drift Exploiter 4” tag, the current balance and, on 23 and 24 July, the run of outgoing transfers are all there. Open the destination, 0xd90e2f925DA726b50C4Ed8D0Fb90Ad053324F31b, and it is the Tornado Cash router; the individual transactions show the round 1, 10 and 100 ether amounts.

The trail ends at the mixer by design. Tornado Cash pools deposits from many users and lets each withdraw to a new address with a cryptographic proof that does not reveal which deposit was theirs. Once the ether is pooled and withdrawn, the public link between the Drift wallet and the cash-out address is gone. Everything before that point is on the record; tracing after that is very difficult (not always impossible).

About $44.4 million has now crossed that line. The remaining $201 million sits in the wallet, visible and flagged, until it moves.

Sources

  1. Chainalysis, Lessons from the Drift hackchainalysis.com
  2. Elliptic, Drift Protocol exploited for $286m in a suspected DPRK-linked attackelliptic.co
  3. TRM Labs, North Korean hackers attack Drift Protocoltrmlabs.com
  4. Drift Protocol, incident recovery updatedrift.trade
  5. ZachXBT on X, on recovering large DPRK exploitsx.com
  6. Etherscan, the Drift Exploiter 4 walletetherscan.io
  7. Etherscan, the Tornado Cash router contractetherscan.io
  8. Onchain Lens on X, the movement, citing Arkhamx.com