Hacker Who Sold ETH at $3,308 Just Bought Back at $2,109: A $5.6M Swing in 9 Months
The same wallet that pumped 17,124 ETH into the market at $3,308 nine months ago just swept 18,273 ETH off the table at $2,109.
That’s a $5.6 million dollar swing – and the hacker still holds $18 million in stablecoins.
⚠️ Deep article forbidden
On August 20, 2024, on-chain analyst Yu Jin flagged a dormant address that suddenly woke up. The address, linked to a prior exploit, had been sitting on a pile of DAI and USDS. At 08:32 UTC, it started buying ETH in batches through a DEX aggregator. Over five hours, it spent 38.535 million DAI/USDS to acquire 18,273 ETH. The average price: $2,109.
But the real story is the sale. Back in November 2023, the same address sold 17,124 ETH at $3,308, pocketing roughly 56.6 million DAI. That was a near-perfect top. Now, after a 36% drop in ETH price, they’re buying back 1,149 more ETH than they sold – and still have ~18 million DAI left.
Context: This isn’t a random trader. The wallet originally received ETH from Tornado Cash, the privacy mixer sanctioned by the U.S. Office of Foreign Assets Control (OFAC). The hacker likely used the mixer to break the on-chain link between their exploit proceeds and their current holdings. But the exit to DEX is fully traceable.
⚠️ Deep article forbidden
Core analysis: Let’s run the numbers.
Sale: 17,124 ETH @ $3,308 = $56.6M
Buyback: 18,273 ETH @ $2,109 = $38.5M
ETH profit: +1,149 ETH (6.7% more ETH)
Stablecoin leftover: $56.6M - $38.5M = $18.1M
In dollar terms, the hacker locked in a $18.1M gain (minus fees) while increasing their ETH stack. That’s textbook “high sell, low buy” – but executed with near-perfect timing. The 9-month gap suggests patience, not panic.
From a behavioral finance lens, this is a contrarian move. The hacker sold when ETH was riding high on L2 hype and ETF speculation, and bought back when the market was in a correction phase, with ETH struggling to hold $2,200. They effectively bet on a recovery – and so far, that bet is paying off.
But there’s a catch. The source of funds – Tornado Cash – means the hacker is sitting on a regulatory time bomb. Any compliant exchange will flag the address. OTC desks might refuse to touch it. Even if the hacker wants to sell again, they may face KYC hurdles. That’s why the leftover 18 million DAI is probably going to stay in DeFi or be laundered through further mixers.
⚠️ Deep article forbidden
Contrarian angle: The market is reading this as a bullish signal – “smart money” buying the dip. But the reality is more nuanced. The hacker’s behavior is a risk management play, not a conviction bet. They already secured their dollar profit. The ETH buyback is a leveraged bet on further upside. If ETH drops below $2,100, the hacker’s net position goes underwater.
Moreover, the use of Tornado Cash means this address is now a “hot potato”. Any exchange that receives funds from this wallet will be under scrutiny. The hacker’s ability to monetize the ETH is limited unless they move it through privacy tools again – which itself carries risk.
Takeaway: This single trade tells us more about the cat-and-mouse game between hackers and regulators than it does about ETH’s price direction. The hacker demonstrated discipline and technical skill, but the regulatory noose is tightening. The next move? Watch the wallet. If the ETH moves to a centralized exchange, we’ll see a compliance test in real-time. If it stays in DeFi, the hacker is signaling they’re out of the traditional finance loop.
As a market surveillance analyst, I’ve seen similar patterns before. The 2022 FTX collapse revealed how hackers use mixers to obscure paths, then re-enter through DEX. This case is a textbook example of “exit liquidity” – but with a twist: the hacker is now the one providing liquidity.
One thing is certain: the on-chain trace is permanent. No amount of mixing can erase the fact that this address now holds 18,273 ETH with a known exploit history. For the rest of us, it’s a reminder that in crypto, the blockchain never forgets.