According to blockchain security company PeckShield, the perpetrator who drained funds from Aztec's outdated Connect storage in June has now sent another 300 $ETH to Tornado Cash, bringing the total amount transferred to this mixer to 500 $ETH.
The significance of the transfer lies not only in its scale but also in its pace. The hacker has already moved about 55% of the 909 $ETH from the initial attack through Tornado Cash, but not in one go—instead, in sporadic amounts. This temporal pattern suggests their exit strategy isn't focused on rapid money laundering, unlike other major crypto heists.
Slowly Dripping into the Mixer
The latest 300 $ETH, worth approximately $572,100 at the time, were deposited into Tornado Cash on August 8. A month earlier, on July 2, the company recorded a deposit of 145 $ETH (about $227,650), bringing the total deposit to 200 $ETH.
The timing of the operation is telling. Instead of moving the stolen $ETH in one transaction, the hacker has been funneling it into the mixer in small batches, with the latest deposit occurring 37 days after the previous one.
#PeckShieldAlert The @aztecnetwork Private Rollup Bridge exploiter deposited 145 $ETH ($227,650) into #TornadoCash.
— PeckShieldAlert (@PeckShieldAlert) July 2, 2026
The exploiter has deposited into #TornadoCash so far. pic.twitter.com/QJpfsdwtTS
This sharply contrasts with the Beanstalk case in 2022. According to Merkle Science, the perpetrators made 270 transfers totaling 24,930 $ETH through Tornado Cash, with most transfers being similar in size and occurring seconds apart.
The Aztec exploiter's slower approach doesn't hide the funds from scrutiny. Tornado Cash was designed to break the on-chain link between deposits and withdrawals, but transaction timing, wallet behavior, and actions outside the mixer can still reveal some information. According to TRM Labs, the company has managed to trace funds concealed by the mixer using behavior and timing correlation, anonymous set analysis, and identification of off-ramps.
Where the 500 $ETH Came From
The source of the stolen funds dates back to June 14, when the cybercriminal withdrew approximately $2.19 million in a single transaction from the deprecated Aztec Connect contract. According to Blockaid, the stolen funds included 909 $ETH, 270,513 DAI, 168 wstETH, and other assets.
During a second attack just a day later, residual assets worth about $88,000 were stolen again from the same outdated system. Blockaid reported that the hacker used the same calculation method to attack remaining positions in the bridging system.
Most importantly, this exploit did not hack Aztec's underlying cryptography. Blockaid discovered a flaw in proof verification and calculation bounds processes, which allowed the hacker to generate balances without deposits backing those balances.
The Aztec Connect service was already deprecated, and Aztec Labs no longer controlled the administrative keys for the affected immutable contracts. The current Aztec Network and the AZTEC token were unaffected.
Why Stolen Funds Continue Flowing into Tornado Cash
The Aztec case exemplifies a broader trend in the crypto world: the number of attacks is rising even as the average number of incidents declines.
According to TRM Labs, the first half of 2026 saw 207 crypto hacks, the highest number for that period. Total losses from crypto hacks amounted to $972 million, less than half the $2.3 billion stolen in the first half of 2025. The number of smart contract exploits in 2026 was 125, with a median damage of about $219,000.
Tornado Cash remains integral to this money laundering system. In June, TRM reported that this mixer accounted for just 20% of global activity in 2026 but remained the leading mixer in Ethereum-based networks, although its share dropped significantly after U.S. sanctions in 2022.
Academic research confirms Tornado Cash's relevance. A study by scientists from the University of Birmingham and the University of Sydney found that Tornado Cash was used in 78.33% of all Ethereum blockchain hacks during the studied period.
The legal landscape has since shifted. The U.S. Treasury lifted sanctions against Tornado Cash on March 21, 2025, after the Fifth Circuit Court ruled that immutable smart contracts are not considered property subject to the jurisdiction of the Office of Foreign Assets Control (OFAC).
For DeFi investors and participants, the Aztec scenario illustrates a broader issue: deprecated contracts can remain economically significant long after a protocol's closure. If significant funds are tied up in outdated technology, this vulnerability can become a source of loss. Moreover, once these funds are stolen, the money laundering methods used by criminals no longer seem novel.
end-content







