Key Insights:
- The attacker has now moved a total of 500 ETH through Tornado Cash following the latest deposit activity.
- The last transfer of 300 ETH occurred after 37 days, indicating a slower and more staggered laundering schedule.
- The money is not entirely untraceable. With even a mixer, the investigators can trace the deposits and the activity before and after them.
Aztec attacker-linked funds moved again on August 8, with 300 ETH entering Tornado Cash. The transfer lifted total deposits to 500 ETH as investigators continue tracking funds from the June exploit.
PeckShield valued the latest transfer at about $572,100 when it reported the movement. The security firm identified three separate deposits of 100 ETH each.

Hacker Takes a Slower Route to Tornado Cash
The August transaction continues a measured movement of funds rather than a rapid exit.
On July 2, PeckShield reported a 145 ETH deposit worth roughly $227,650. The latest transfer came 37 days later and pushed cumulative Tornado Cash deposits to 500 ETH.
At reported prices, those deposits carried a combined value of about $953,000.
That pattern differs from laundering activity seen after several previous cryptocurrency exploits. The attacker has used irregular transaction sizes and long gaps between major transfers.
For comparison, criminals behind the 2022 Beanstalk incident took a far more aggressive approach. Merkle Science recorded 270 transfers involving 24,930 ETH through Tornado Cash. Many of those transactions occurred within seconds and carried similar amounts.
The Aztec attacker has instead stretched activity across weeks. However, slower transfers do not necessarily prevent investigators from following wallet behavior.
TRM Labs has previously tracked mixer-linked funds using timing patterns, behavioral correlations, anonymity analysis, and identifiable off-ramps.
June Exploits Exposed Risks in Legacy Contracts
The funds trace back to attacks involving discontinued Aztec infrastructure in June.
On June 14, an attacker drained roughly $2.19 million from old Aztec Connect contracts. Blockaid identified 909 ETH, 270,513 DAI, 168 wstETH, and other assets among the stolen funds.
Another incident followed one day later and removed about $88,000 from remaining bridge positions. Security researchers traced the weakness to proof verification and settlement processes. The attacker could create balances without corresponding deposits backing them.
The breach therefore did not compromise the underlying cryptography used by the active network. Aztec Connect had already reached end-of-life status before the attack. Moreover, Aztec Labs had surrendered administrative control over the affected immutable contracts.
That structure prevented the company from pausing or upgrading them after researchers identified the vulnerability.
Key figure Reported amount
Latest Tornado Cash transfer 300 ETH
Total mixer deposits 500 ETH
Latest transfer value About $572,100
Reported June bridge loss About $2.165 million
Previous major deposit 145 ETH
Gap between major transfers 37 days
Legacy Infrastructure Creates a Longer Security Tail
The attack highlights a difficult problem for decentralized finance projects with discontinued contracts.
A protocol can retire its software while assets remain locked inside old infrastructure. Immutable contracts make that challenge harder when developers surrender administrative controls.
The current Aztec Network and AZTEC token were not affected by the legacy contract exploits. However, the situation demonstrates the financial value of infrastructure that’s no longer being supported by its developer.
The broader security situation is also precarious. In the first half of 2026, TRM Labs has reported 207 cryptocurrency hacks. The total losses due to those incidents were about $972 million.
That total remained below the $2.3 billion stolen during the same period in 2025. Yet the number of attacks reached a record for the period. Smart-contract exploits accounted for 125 incidents, while the median loss stood near $219,000.
Tornado Cash continues to be pivotal for fund tracking.
Despite the significant changes in the legal status, Tornado Cash remains a part of investigations of stolen cryptocurrency.
The mixer separates the deposit and the withdrawal addresses, making it more difficult to trace the transactions on the blockchain directly. Investigators can still review any surrounding wallet activity and time of transactions, however.
According to TRM Labs, the share of Tornado Cash in mixer activity in 2026 was approximately 20%. It still was one of the top mixers for any Ethereum-based network, though.
The regulatory environment has also changed.
The U.S. Treasury removed Tornado Cash from its sanctions list on March 21, 2025. That action followed litigation over whether immutable smart contracts constituted sanctionable property.
U.S. authorities have continued scrutinizing cryptocurrency mixers in investigations involving cybercrime, sanctions evasion, and illicit financial flows.
Conclusion
Aztec now faces a security story extending beyond the original June attacks. Attention has shifted toward where the stolen assets travel and how quickly they move.
The attacker’s measured approach may complicate recovery, but the blockchain still provides investigators with visible activity around mixer deposits. Further wallet movements could reveal whether remaining assets follow the same route.









