The individual responsible for draining funds from Aztec’s deprecated Connect rollup in June has now transferred a total of 500 ETH to Tornado Cash, according to blockchain security firm Peck
The individual responsible for draining funds from Aztec’s deprecated Connect rollup in June has now transferred a total of 500 ETH to Tornado Cash, according to blockchain security firm PeckShield. This follows an additional 300 ETH sent to the mixer, highlighting an evolving approach among cybercriminals to laundering stolen assets from decentralized finance contracts.
Patterned withdrawals raise new questions
Unlike some previous high-profile incidents, the exploiter opted for smaller, sporadic transfers instead of a swift and single deposit. The recent 300 ETH move, worth approximately $572,100 at the time, was recorded on August 8. PeckShield had earlier identified a 145 ETH deposit on July 2, valued at about $227,650, pushing the cumulative sum moved through Tornado Cash to 200 ETH before the latest activity.
This deposit occurred 37 days after the preceding transfer, suggesting a deliberate, calculated timetable. Rather than moving all 909 ETH siphoned in the original hack at once, the attacker broke the sum into small tranches, transferring about 55% so far across multiple sessions.
The slow movement of funds via Tornado Cash stands in marked contrast to cases like the 2022 Beanstalk incident, where perpetrators executed 270 transactions involving 24,930 ETH within moments of each other, exploiting the anonymity of the mixer but relying on speed.
In the case of Aztec, TRM Labs noted that patterns in transaction timing, wallet activity, and behavior outside the mixer can still yield valuable clues. Despite the intent to mask asset movement, modern analytics tools, including behavioral correlation and off-ramp monitoring, have helped track even funds routed through mixing protocols.
Origins of the Aztec exploit
On June 14, an attacker exploited vulnerabilities in outdated Aztec Connect rollup contracts, securing roughly $2.19 million through a single transaction. According to Blockaid, the stolen assets included 909 ETH, 270,513 DAI, 168 wstETH, and additional tokens.
A follow-up incident saw the same attacker drain another $88,000 in residual funds from the legacy protocol just a day later, using nearly identical methods to empty the remaining bridge positions.
Investigation into the method revealed that the underlying cryptography of Aztec was not compromised. Instead, Blockaid identified a flaw in proof verification and settlement handling, which enabled the hacker to generate synthetic balances unsupported by corresponding deposits.
The affected contracts had already been deprecated, and Aztec Labs no longer controlled their administrative keys. This meant the main Aztec Network and current AZTEC token were not impacted by the attack.
Cyclical trends in crypto laundering
The Aztec incident adds to a persistent pattern in blockchain security. TRM Labs reported 207 crypto hacks in the first half of 2026, resulting in $972 million in losses. Although the total amount stolen fell sharply compared to the $2.3 billion lost during the same period in 2025, the actual number of attacks rose, with 125 smart-contract exploits and a median loss of $219,000 per incident.
Tornado Cash has continued to feature prominently in the movement of illicit funds, reportedly accounting for 20% of all global mixer transactions so far in 2026. Despite a decrease in overall market share following U.S. sanctions imposed in 2022, it remains a dominant service on Ethereum-based platforms.
Academic studies from the University of Birmingham and University of Sydney indicate that Tornado Cash facilitated 78.33% of hacking events on Ethereum within the examined period, demonstrating its continued relevance among cybercriminals, even after attempts at regulatory suppression.
In March 2025, the legal environment shifted when the U.S. Treasury lifted sanctions against Tornado Cash. The determination by the Fifth Circuit clarified that immutable smart contracts do not fall under the Office of Foreign Assets Control’s property jurisdiction.
For users and decentralized finance participants, the slow withdrawal strategy observed in the Aztec scenario underscores the enduring risks of legacy smart contracts. Funds residing in outdated protocols remain vulnerable, and once stolen, the laundering techniques seldom deviate from established norms.
Amid heightened market scrutiny of attack patterns and technical weaknesses, comprehensive tracking of wallet flows, transaction size, and timing becomes increasingly vital. Platforms like CryptoAppsy, which require no account creation hassle, combine real-time crypto prices, portfolio management, macroeconomic data such as Fed interest rates, and customizable alerts in a unified dashboard—making it easier for investors to monitor key indicators and respond rapidly to market-moving events.
The post Aztec exploit hacker sends 500 ETH to Tornado Cash after $2.19 million theft appeared first on COINTURK NEWS.