The Second Dip
Just over two weeks ago, the Solana OG attacker quietly tested the waters. A few hundred ETH slipped into Tornado Cash.
This week, they dove in headfirst. Onchain Lens flagged the transfer: 2,290 ETH β roughly $4.39 million β moving from the attacker's known address cluster into the sanctioned privacy pool on Ethereum mainnet. Not a bridge. Not a centralized mixer. Not a fresh layer-2 hop. The same protocol they used before, in the same denomination pools, with the same patient rhythm.
This is not breaking news in the sense that it changes markets. It won't move BTC. It won't crash a token. But it is news in a deeper sense β it is a window into how a criminal mind operates under the full glare of Chainalysis, Elliptic, and every blockchain intelligence firm on Earth. And what I see in that window is both more calculated and more revealing than the headlines suggest.
Because here is the uncomfortable truth: the attacker is not running. They are methodically, deliberately cleaning house β and the tracking window is closing.
Backstory: A Heist, Then Silence
For those who didn't follow the original event: roughly a month ago, a wallet associated with the Solana ecosystem β referred to in community intelligence as "Solana OG" β suffered a breach of approximately $14.2 million. The mechanics of the initial exploit were never fully resolved in public, and the victim entity has remained quiet. What matters for this analysis is what happened after.
Instead of panic-bridging funds through every available rail, the attacker went still. For weeks, nothing. No movement on the tagged addresses, no suspicious activity alerts, no exchange deposits. Then, about fourteen days ago, the first ripple appeared: a modest test transfer into Tornado Cash on Ethereum mainnet. It was small enough to be missed by casual observers, large enough to be intentional.
Now, the second wave: 2,290 ETH in clearly structured batches. For anyone who has studied money laundering flows β and I have spent years doing exactly that, first as a student building Python tools to decode whitepapers, later as a community analyst watching EIP-1559 anxiety distort people's understanding of fee mechanics β this pattern is textbook. It follows the classical three-phase structure of laundering: placement, layering, and integration.
Placement: the stolen ETH sits dormant, waiting for heat to dissipate. Layering: the funds are broken into tranches and pushed through a zero-knowledge mixer to sever the on-chain link. Integration: the attacker withdraws to fresh addresses and eventually funnels into exchanges, DeFi, or long-term cold storage.
We are witnessing the layering phase in real time. The question is how much runway remains before it completes.
The Technical Core: What the Pattern Reveals
Let's get specific about what this second transfer tells us β not just about the funds, but about the person or team behind them.
First, the denomination strategy. The attacker moved 2,290 ETH into Tornado Cash's privacy pools. Those pools are not uniform β they are segmented by denomination: 0.1 ETH, 1 ETH, 10 ETH, 100 ETH. Each pool has its own anonymity set, its own merkle tree, its own deposit and withdrawal dynamics. The choice of which denominations to use matters enormously.
A novice would dump everything into the 100 ETH pool and hope for the best. That is actually a mistake β the 100 ETH pool historically has a smaller anonymity set, meaning the statistical correlation window is tighter. An average user would split between 10 and 100 ETH pools. The attacker's behavior suggests they understand the tradeoff between liquidity and anonymity, and have deliberately chosen a mix that maximizes the probability of a clean exit.
Second, the timing discipline. Two transfers, roughly two weeks apart β not one massive move, not three rapid-fire chips. This is characteristic of what I call "threshold laundering": moving amounts large enough to be useful, small enough to avoid triggering exchange risk engines that have been calibrated to flag sudden whale movements. The first transfer functioned as a test β checking that withdrawals work, that relayers still operate, that the sanctions hadn't broken the protocol's fundamental functionality. It also functions as a decoy: every monitoring team that noticed the first transfer is now watching the original deposit addresses, while the attacker has already moved a portion of the funds to fresh, untagged addresses.
Third, the asset choice. The attacker held ETH. Not USDC, not DAI, not wBTC β ETH. This is a deliberate choice. ETH requires no KYC on withdrawal. It can be swapped on-chain without touching a compliant frontend. It is the native asset of the privacy pool itself, requiring no wrapping, no bridge latency, no added attack surface. The attacker is not simply trying to make money β they are trying to make money untraceable, and ETH is the optimal vehicle for that goal on Ethereum mainnet.
Here's where my own technical lens sharpens. I have spent the past eight years watching DeFi protocols break, heal, and re-break. I have walked through the EIP-1559 fee-burning confusion with hundreds of beginners. I have audited trust assumptions in community-run tools. And what I can tell you is this: the person moving these funds has a working understanding of how Ethereum's privacy landscape actually functions.
That might sound like a low bar. It is not. Most criminals in crypto are opportunists β they steal, then immediately try to cash out through a centralized exchange, often tripping their own alarms. The Solana OG attacker has demonstrated the opposite instinct: patience, protocol literacy, and a clear understanding that the bottleneck in this game is not the mixing β it is the exit.
Every mixer in the world can anonymize a transaction. What is hard is turning anonymous ETH into fiat without creating a new trail. That is the integration phase, and it is where most laundering schemes collapse. The attacker knows this. Which is why the remaining ~$9.8 million they still control is the single most important thing to watch in this case.
The Relayer Problem Nobody Is Talking About
Let me take you into an operational detail that almost no mainstream coverage of this story will mention: the relayer ecosystem.
Tornado Cash is not a single monolithic service. It is a set of immutable smart contracts that rely on a distributed network of relayers β entities that submit transactions on behalf of users and front them the gas fees. When OFAC sanctioned the protocol in August 2022, the vast majority of public relayers shut down. They were US-based, they were incorporated in friendly jurisdictions, they did not want to face prosecution.
But here is the thing I have learned from watching this ecosystem for years: sanctions do not kill protocols. They kill corporate entities. The pseudonymous infrastructure survives.
New relayers emerged β community-maintained, geographically distributed, sometimes operating from jurisdictions that do not recognize OFAC's reach. Their fees are higher. Their interfaces are less polished. But they are there. The fact that the Solana OG attacker successfully moved funds into Tornado Cash twice β not once, but twice β is proof that this unauthorized relayer layer is functioning, and functioning with enough reliability that an attacker with multi-million-dollar assets considers it their primary laundering tool.
This should concern regulators more than it likely does. The narrative has been: "sanction the protocol, and the protocol dies." The empirical reality is: "sanction the protocol, and the protocol goes gray β driven underground, operated by the very criminals it was meant to constrain, with no oversight whatsoever."
I am not arguing for or against the sanctions here. I am pointing out a glaring blind spot in the strategy. You cannot remove a piece of pseudonymous infrastructure from a pseudonymous network by issuing legal threats to its visible operators. The contracts continue to run. The ZK-SNARK proofs continue to be generated. The anonymity sets continue to grow. The only thing that changed is that legitimate users left, which paradoxically made the protocol more valuable to criminals.
What the Compliance Industry Sees (and Doesn't)
Now let's spend a moment inside the analytical tooling that institutions actually use, because this is where my experience training Deutsche Bank executives and building "Crypto Literacy for Executives" programs sharpens the picture.
Chainalysis, Elliptic, and TRM Labs do not track Tornado Cash by watching the smart contract β that is pointless. They track behavioral fingerprints around the protocol: the gas source of the deposit transaction, the funding history of the depositing address, the timing patterns, the withdrawal address's subsequent interactions. When the attacker deposits into Tornado Cash, they are trying to dissolve that fingerprint. And for the most part, the ZK proof does its job β the withdrawal side is genuinely disconnected from the deposit side in cryptographic terms.
The catch is everything outside the proof. The deposit transaction's metadata. The withdrawal address's eventual connections. The exchange account that eventually receives the cleaned funds and runs them through KYC. That is where the analytical battle is actually fought.
And this is precisely why the attacker's decision to repeat their use of Tornado Cash is strategically intelligible: they are betting on the gap between cryptographic anonymity and operational discipline. The protocol guarantees the former. The attacker's discipline controls the latter.
Over my years in this industry β from building ChainLit to watch students avoid OneCoin-style fraud, to running DeFi education sessions during the 2020 summer, to founding Resilience DAO in the FTX winter β I have seen exactly how these gaps get exploited. It is never the cryptography that fails. It is always the human layer around it.
The Contrarian Read: This Is Not a Sign of Privacy's Death
The conventional take on this story will be predictable: "Attacker uses Tornado Cash β privacy tools are a threat to society." It writes itself. Regulators will cite this case in hearing rooms. Compliance vendors will cite it in marketing materials.
But the contrarian angle β the one I keep circling back to β is that this event proves precisely the opposite of what the "privacy equals crime" crowd wants you to believe. This event proves that sanctioned, ostensibly dead privacy infrastructure remains the single most effective laundering tool in all of crypto. That is not a moral endorsement. It is an empirical observation.
The reason is straightforward: adversarial creativity does not require legal gray zones when the underlying technology is structurally gray. Tornado Cash's ZK-SNARK design provides genuine, verified anonymity. The offensive security community has spent years probing it and has not found a single cryptographic break in the core withdrawal mechanism. That longevity β from 2019 through years of sanctions and prosecution β is a kind of survival that rivals legitimate DeFi protocols.
The uncomfortable implication is this: privacy is not dying in crypto. It is going underground. And the people who still need it most β dissidents in repressive regimes, journalists protecting sources, victims fleeing surveillance β are being collateral damage in a war aimed at criminals. The tool is not the enemy. The use case is what matters. But regulators have traded nuance for expediency.
The second contrarian observation is even more uncomfortable: this event did not hurt the attacker. They moved funds successfully. They moved them twice. They are likely to move them a third time. Every successful move reinforces the message to every other hacker in the ecosystem: Tornado Cash works, regardless of what the OFAC says. That is the learning signal that propagates through the black-hat community. And it is a stronger signal than any enforcement action, because it comes from lived experience.
I think about this from a community perspective. In 2022, after FTX collapsed, I watched the industry collectively despair. I founded Resilience DAO to support displaced workers, and in that process I internalized something that has shaped everything I have written since: community is the only chain that cannot be broken. That principle applies to legitimate communities and, I regret to say, to illicit networks as well. The attacker's community β the informal network of operators, relayers, and technical resources that keeps this kind of laundering operational β is functioning precisely because it is resilient, distributed, and bound by shared purpose.
We ignore that mirror at our own peril.
The $9.8 Million Question
Let me return to the numbers. The original theft was about $14.2 million. This transfer moved $4.39 million. The earlier transfer β let's conservatively estimate $1 million. That leaves roughly $8.8 to $9.8 million still sitting in attacker-controlled addresses.
That is a lot of oxygen in the room. And it tells me several things.
First, the attacker is in no hurry. They have left the majority of their loot untouched, which is psychologically interesting. Most thieves want to convert their profits immediately. This operator is playing the long game β perhaps waiting for a more favorable market cycle, perhaps waiting for law enforcement attention to shift elsewhere, perhaps already routing the remaining funds through non-custodial tools that are harder for even sophisticated analytics to see.
Second, the decision to move in tranches suggests the attacker views this as a series of risk-adjusted decisions rather than a single gamble. Each transfer is a bet that this particular batch will not be flagged. Each success reduces their overall exposure. The cumulative effect is that, with each passing week, the practical chance of law enforcement identifying the full scope of the theft decreases.
Third β and this is the point I want every monitoring team to internalize β the next transfer may not look like the last two. The attacker has already demonstrated the capacity to vary their approach. The next move might be a swap to a different asset on a privacy-preserving decentralized exchange. It might be a bridge to a cheaper chain where transactional analysis is less mature. It might be a long rest in cold storage.
If I were advising the victim entity or the exchange involved, my single instruction would be: treat the remaining ~$9.8 million as the live problem. The $4.39 million that just entered Tornado Cash is effectively gone from the public ledger. The funds that are still visible are the ones you have a realistic chance to influence.
This is the part where I have to be honest about my own biases. I have spent years evangelizing the idea that transparency on-chain can be a force for good β that public, verifiable data gives us the ability to hold bad actors accountable. That belief is still true. But events like this one remind me that transparency is directional: it shows us the problem while sometimes blinding us to the solutions. The attacker knows they are being watched. That is why they are using Tornado Cash. The watching itself is not a deterrent β it is a variable in their cost-benefit calculus.
The Quiet Efficiency of Crime Infrastructure
Let me zoom out for a moment, because this event is not isolated. It is a data point in a broader trend that I have watched develop over the past four years.
Throughout the 2020 DeFi summer and the 2021 bull run, the dominant image of crypto crime was the "lazy hack" β someone who exploits a bug and immediately tries to convert the funds at the nearest DEX, often losing a huge fraction to slippage or getting caught by simple tracing. Those attacks still exist. But the sophisticated segment has evolved.
Modern crypto crime infrastructure includes:
- Specialized mixing tools that offer, ahead of Tornado Cash, no withdrawal fees for large users.
- Cross-chain bridges that deliberately obfuscate source chains.
- Private RPC providers that hide IP addresses and metadata.
- Mesh networks of relayers that rotate constantly to avoid blacklists.
- "Smart" position management β the attacker's funds may be earning yield in obscure lending protocols while awaiting laundering.
The Solana OG attacker is using only a fraction of this toolkit. Tornado Cash is the most battle-tested piece, and their choice to stick with it tells me they are probably part of an established network β perhaps a group that has used these rails before, perhaps an individual following a playbook handed down through the ecosystem's darker channels.
One detail I want to flag: in my experience training institutional clients, the question I get most often is some variation of "Why can't we just ban the tools?" The answer, difficult as it is, is that banning a smart contract is not like banning a website. The contract runs wherever Ethereum runs. You cannot selectively delete it. You cannot force it to update. You can only surround it with legal risks β which drives legitimate use away while leaving the tool itself functionally intact for those who accept the risk.
That is what we are seeing here. Tornado Cash has been struck by one of the most powerful enforcement tools in the American arsenal, and it is still processing multi-million-dollar deposits for the people it was never designed to help.
The Ethical Reckoning
Something else this event triggers in me β and I want to put it out in the open because I think too many people in this industry avoid it β is the question of what we are actually building toward. In my manifesto on algorithmic accountability, I argued that code must reflect human values. Tornado Cash was built with a specific human value in mind: privacy. Its creators believed β and I think honestly still believe β that privacy is a fundamental right, not a privilege for the law-abiding or a commodity for the wealthy.
Then their creation was used to hide stolen funds. Then the creators were prosecuted. Then the tool went underground. And now, ironically, the very mechanism that was supposed to protect ordinary people's financial privacy has become a liability to the privacy narrative itself.
This is the deep tension that makes me both an enthusiastic endorser of decentralization and a sober critic of its blind spots. The blockchain gives us neutrality: a smart contract does not ask who you are or why you are transacting. But neutrality is not the same as justice. It simply removes judgment from the equation β and then judgment re-enters through other means: sanctions lists, exchange blacklists, law enforcement subpoenas.
I do not have a tidy answer. I know that privacy is essential. I also know that crime is real. Tornado Cash sits at the intersection of both truths, unmoved by either. The ethical reckoning we need β as an industry, as a community β is to design systems that offer meaningful privacy while preserving accountability for genuine harm. Selective disclosure. Voluntary compliance mechanisms. Post-hoc judicial review. These are not impossible. They are just hard, and the industry has not yet sufficiently invested in them.
Until then, stories like this one will keep repeating. And each repetition will widen the gap between the "privacy is a human right" camp and the "privacy is a crime accelerator" camp.
I know which camp I sit in. I have seen too many journalists, dissidents, and vulnerable people rely on on-chain privacy to believe that its total elimination would make the world safer. But I also know that clinging to zero-accountability privacy is a losing strategic position. The middle path β compliance-ready privacy, built for legitimate use β is the only one that can survive the next decade.
What to Watch Next
Let me close with a concrete monitoring checklist. If you are tracking this case, or any case like it, here is what I would be watching for over the next four to six weeks:
First: the third transfer. The attacker has demonstrated a rhythm. If a third deposit of significant size appears β particularly one above 500 ETH β it should be read as confirmation that the remaining balance is being laundered at a deliberate pace. That is the moment when the tracking window genuinely closes.
Second: the integration attempt. Eventually, the attacker will need to convert mixed ETH into something spendable. Watch for withdrawals from Tornado Cash that fund newly-created wallets, which then deposit to centralized exchanges within a short window. The probability of integration is low in the next month β these operators know that fresh exchanges undergo stricter review β but the first integration attempt is the single most likely point of arrest.
Third: regulatory reaction. If OFAC or another authority issues a new statement about Tornado Cash usage, or if the Justice Department references the Solana OG case in any filing, it will signal escalating enforcement focus. Conversely, silence from the regulators would indicate that they have already moved on β a signal that the attacker's strategy is working.
Fourth: the privacy narrative. Watch how journalists and influencers cover this story in the coming week. Every time a "hacker uses Tornado Cash" headline circulates, the political temperature around privacy tools rises another degree. If the narrative shifts toward "criminals use whatever works," the industry will have a harder time defending legitimate privacy use cases.
I will be watching all four signals. Not because I have a stake in the Solana OG outcome specifically, but because this case functions as a stress test for the entire privacy-enforcement ecosystem. If the attacker successfully disappears $14.2 million into the void, it will be the most consequential precedent in crypto crime this year.
The Long View
Here is my conclusion, and it is not a comfortable one.
We are watching a game of asymmetric information play out in real time. The attacker holds the cards: they know which addresses they control, which tools they use, and when they will move next. The tracking community holds a different set: transactional visibility, behavioral analytics, and the hope that the attacker makes a single operational mistake.
For a while now, the attacker has been winning. They have moved funds. They have not been caught. They are likely to move more.
But I have covered enough of these cases to know that the game is not over. Criminal launders eventually have to re-enter the legitimate financial system β through an exchange, a merchant, a tax filing, a lifestyle choice that cannot be made in crypto. When that moment comes, the KYC trail reattaches. The chain that was severed at Tornado Cash reconnects in the real world.
That is my hope, and it is not naive. It is based on years of watching the crypto ecosystem prove that it can be exploited β and then watching it prove, time and again, that it can heal. Community is the only chain that cannot be broken. The attacker is trying to break that chain. But the community of analysts, builders, and everyday users who keep each other safe has a resilience that no amount of mixed ETH can dissolve.
Trust is built in the bear market and spent in the bull β but it is also rebuilt in the messiest moments, by the people who stay through the storm. The Solana OG attacker is a storm. They are not the horizon.
The industry's response to this moment will shape how we think about privacy, crime, and accountability for years to come. I would rather we enter that conversation with clear eyes and open community β ready to protect the innocent, prosecute the guilty, and build the tools that serve both goals at once.
Because in the end, that is the only chain that holds.