The attacker who drained Aztecās deprecated Connect rollup in June has now sent another 300 ETH to Tornado Cash, bringing the total moved to the mixer to 500 ETH, according to blockchain security firm PeckShield.
The importance of the transfer lies not simply in magnitude, but also in speed. The hacker has already transferred about 55% of the 909 ETH used in the original attack through Tornado Cash, but they did so in inconsistent amounts instead of a single transaction. Such patterned timing indicates that its exit strategy does not involve rapid laundering like other major crypto attack schemes.
A slow drip into the mixer
The latest 300 ETH, worth roughly $572,100 at the time, was deposited into Tornado Cash on August 8, PeckShield reported. A month earlier, on July 2, the firm flagged a 145 ETH deposit worth about $227,650, bringing the running total to 200 ETH.
The timing reveals a lot. Rather than transferring the stolen ETH in a single transaction, the hacker has transferred the stolen ETH to the mixer in small batches, with the last deposit occurring 37 days after the previous transaction.
#PeckShieldAlert The @aztecnetwork Private Rollup Bridge exploiter-labeled address has deposited 145 ETH ($227,650) into #TornadoCash.
So far, the exploiter has deposited a total of 200 ETH into #TornadoCash. pic.twitter.com/QJpfsdwtTS
ā PeckShieldAlert (@PeckShieldAlert) July 2, 2026
This is in stark contrast to the Beanstalk incident in 2022. According to Merkle Science, the criminals carried out 270 transfers of 24,930 ETH through Tornado Cash, with most of the transfers being similar in size and taking place within a few seconds of each other.
The slower approach of the Aztec exploiter does not hide the funds from examination. Tornado Cash was created to cut the on-chain relationship between deposits and withdrawals, but the time of the transaction, the behavior of the wallet, and the actions outside of the mixer can still reveal some information. According to TRM Labs, the firm managed to track funds hidden by the mixer with the help of behavioral and timing correlation, anonymity set analysis, and off-ramp identification.
Where the 500 ETH came from
The origins of the stolen funds go back to June 14, when a cybercriminal siphoned off roughly $2.19 million from obsolete Aztec Connect roll-up contracts using one transfer. As per Blockaid, the stolen money includes 909 ETH, 270,513 DAI, 168 wstETH, and other assets.
In the second attack, which occurred just one day later, about $88,000 worth of residual assets was once more stolen from the same legacy system. Blockaid reported that the hacker used the same settlement method to target the remaining bridge positions.
The most important part of the discovery is that the exploit did not break the underlying cryptography of Aztec. Rather, Blockaid found a defect in the proof verification and settlement boundaries processes which allowed the hacker to generate balances without deposits backing those balances.
Aztec Connect had already been deprecated, and Aztec Labs no longer controlled the administrative keys for the affected immutable contracts. The current Aztec Network and AZTEC token were not affected.
Why stolen funds still flow to Tornado Cash
The case of Aztec is an example of a wider trend in cryptocurrency: that attacks are rising in number even as the average value per incident decreases.
According to TRM Labs, there were 207 crypto hacks in the first half of 2026, which is the highest number of hacks recorded in that duration. The total losses in crypto hacks accounted for the amount of $972 million, which is less than half of the money stolen in the first half of 2025, which was $2.3 billion. The number of smart-contract exploits in 2026 amounted to 125, while the median loss was about $219,000.
Tornado Cash is still an integral part of that laundering system. TRM reported in June that the mixer was responsible for a mere 20% of worldwide mixer activity in 2026 and that it was still the leading mixer on Ethereum-based networks as of now, although there was a substantial drop in its share after the U.S. sanctions imposed in 2022.
Academic research shows the relevance of the Tornado Cash service. In a study conducted by scholars from the University of Birmingham and the University of Sydney, it was found that Tornado Cash was used in 78.33% of all hacking events on the Ethereum blockchain during the period investigated.
Since that time, the legal environment has evolved. The U.S. Treasury lifted its sanctions against Tornado Cash on March 21, 2025, after the Fifth Circuit determined that smart contracts that cannot be altered are not considered property under the jurisdiction of the Office of Foreign Assets Control (OFAC).
For both investors and DeFi participants, the Aztec scenario is an example of a wider issue: that terminated contracts can be economically relevant long after a protocol is abandoned. If important funds are tied up in outdated technology, this weak point can become a source of losses. Moreover, once this money is stolen, the money-laundering techniques used by criminals do not seem new at all.
Ā
If you’re reading this, youāre already ahead. Stay there with our newsletter.
Ā
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.
