Why the UXLINK hacker’s 14,336 ETH transfers raise fresh questions for DeFi

ambcryptoPublished on 2026-07-05Last updated on 2026-07-05

Abstract

Recent on-chain activity reveals the UXLINK exploiter is actively laundering stolen funds, complicating tracing efforts. The September 2025 hack, which exploited a 'delegateCall' vulnerability to steal roughly $4.5 million, involved converting illicit assets into DAI and Ethereum. Recently, the attacker swapped over 10 million DAI for approximately 6,000.8 ETH and has deposited a total of 14,336.6 ETH into the privacy mixer Tornado Cash in recent weeks, including over $8.1 million worth in a single move. Simultaneously, wallets connected to the defunct Mining Express Ponzi scheme have been converting long-held assets, swapping 5,004 ETH for 8.8 million DAI. Following a separate exploit of the Jaredfromsubway.eth MEV bot, about $5.1 million was also routed to Tornado Cash. These incidents underscore a critical vulnerability in DeFi: while enabling permissionless transfers, the ecosystem lacks effective mechanisms to halt or manage illicit funds once in motion, allowing them to be moved and concealed relatively easily. This highlights the need for strengthened cross-network coordination and real-time threat detection to better safeguard the space.

Recent on‐chain activity shows the UXLINK exploiter actively laundering stolen funds to make them harder to trace.

For background, the UXLINK exploit occurred in September 2025. At the time, the hackers took over the project’s multisignature wallet by taking advantage of a ‘delegateCall’ vulnerability.

They created billions of illegal UXLINK tokens, draining about $4.5 million in cryptocurrency assets. The stolen money was then transferred between several wallets and exchanged for DAI (a stablecoin that is pegged to the U.S. dollar) and Ethereum [ETH].

UXLINK exploiter launders stolen funds

After the attack, the hacker exchanged the remaining DAI tokens for about 6,000.8 ETH.

Source: PeckShieldAlert/X

Following which, the exploiter immediately deposited 6,038 ETH into Tornado Cash following the swap. In fact, in the past two weeks, the attacker has deposited 14,336.6 ETH into Tornado Cash.

Most recently, the attacker laundered stolen assets by converting millions of DAI into ETH and depositing more than $8.1 million worth of ETH into Tornado Cash.

Mining Express faces a similar issue

At the same time, wallets associated with the defunct Mining Express scheme appear to be reallocating long-held assets. The wallet linked to the purported Ponzi scheme changed its holdings into a more liquid stablecoin by exchanging 5,004 ETH for 8.8 million DAI.

For context, Kaze Fuziyama founded Mining Express in 2019. Back then the company allegedly deceived investors with an MLM-based cryptocurrency mining scheme. Soon after that, the company went bankrupt, which pushed the Ukrainian authorities for further investigation in 2022.

Source: Specter/X

After receiving 4,512 ETH in 2024, the associated wallet staked funds via Lido and Ether.fi before fully unstaking them in May 2026. More recently, about $5.1 million of the $7.5 million was moved to Tornado Cash following the exploitation of the Jaredfromsubway.eth MEV bot.

Where is the gap?

It’s evident that although the ecosystem facilitates smooth, permissionless asset transfers, it still lacks efficient systems to stop or deal with illegal funds once they are in motion. In fact, once illegal funds are in the DeFi ecosystem, it is still relatively easy to move and hide them.

Therefore, to safeguard decentralization and user privacy, protocols must strengthen cross‐network coordination and implement real‐time threat detection.


Final Summary

  • The UXLINK reportedly swapped the remaining 10.54 million DAI for 6,000.8 ETH, and a wallet linked to Mining Express swapped 5,004 ETH for 8.8 million DAI.
  • These, along with other exploits and money laundering, reveal a significant crack in the DeFi ecosystem.

Trending Cryptos

Related Questions

QWhat vulnerability did the hackers exploit to carry out the UXLINK attack in September 2025?

AThe hackers took advantage of a 'delegateCall' vulnerability to take over the project's multisignature wallet.

QHow did the UXLINK exploiter launder the stolen funds, and what tool was primarily used?

AThe exploiter laundered the funds by converting stolen DAI into ETH and then depositing the ETH into the privacy mixer Tornado Cash. Over two weeks, they deposited 14,336.6 ETH into Tornado Cash.

QWhat was the Mining Express scheme, and how are its associated wallets currently moving assets?

AMining Express was an MLM-based cryptocurrency mining Ponzi scheme founded in 2019. Associated wallets are now reallocating long-held assets, such as swapping 5,004 ETH for 8.8 million DAI and moving funds to Tornado Cash.

QWhat key problem in the DeFi ecosystem does the article highlight based on these incidents?

AThe article highlights that while DeFi facilitates permissionless transfers, it lacks efficient systems to stop or deal with illegal funds once they are in motion, making it relatively easy to move and hide stolen assets.

QWhat solutions does the article suggest to address the vulnerabilities exposed by these exploits?

AThe article suggests that protocols must strengthen cross-network coordination and implement real-time threat detection to safeguard decentralization and user privacy.

Related Reads

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ETH (ETH) are presented below.

活动图片