I’ve been watching the mempool for weeks. Pattern recognition is a skill I honed auditing MakerDAO’s governance contracts in 2017—a six-month deep dive into stability fee logic that eventually uncovered a critical solvency flaw. That experience taught me to read the silence between transactions. So when a cluster of addresses linked to the Solana OG attacker suddenly deposited 2,290 ETH into Tornado Cash on August 14, 2024, I felt a familiar chill. This is not just a transaction. It is a confession.
Make no mistake: the attacker is not a novice. The same address group had already moved a similar batch about two weeks earlier. Total stolen from the original exploit—likely a Solana-based project or early investor (“OG”)—is around $14.2 million. This latest transfer, valued at $4.39 million at current rates, leaves roughly $9.8 million still sitting in transparent wallets. The attacker is deploying a classic batch-and-sweep strategy: split the loot, deposit into Tornado Cash’s anonymity pools (0.1, 1, 10, or 100 ETH denominations), and withdraw to fresh addresses. Each step is deliberate. Each step is a gamble.
Context: The Protocol That Refuses to Die
Tornado Cash is the most battle-tested privacy mixer on Ethereum. Launched in 2019, it uses ZK-SNARKs to break the on-chain link between depositor and withdrawer. You put in ETH, get a private note, and later redeem it from a new address. The math is elegant. The code is audited. But in August 2022, the U.S. Treasury’s OFAC sanctioned the protocol, making it illegal for American entities to interact with it. The core developers were arrested. The front ends were shut down. Yet the smart contracts remain immutable, and the relayers—though thinned—still operate.
Why does the attacker keep coming back to Tornado Cash? The answer is simple: liquidity. No other mixer on Ethereum has the depth of anonymity sets. Cross-chain bridges are faster but leave a trail through wrapped tokens and bridge validators. On-chain analytics firms like Chainalysis can still cluster deposit and withdrawal addresses if the time window is short. Tornado Cash, with its 0.1 ETH pool holding thousands of notes, offers genuine plausible deniability. The attacker is betting that the noise of the pool will drown out their signal.
Core: The Technical and Ethical Anatomy of the Transfer
Let me walk through what happened—from my perspective as someone who has spent years pulling apart smart contracts to understand their moral weight.
First, the mechanics. The attacker funded a series of deposit addresses (likely from a master wallet that controlled the stolen funds). Each deposit was a transaction of roughly 100 ETH, spread over several hours to avoid drawing attention to the mempool. The total gas spent was around 0.8 ETH—a cost the attacker willingly paid for the fog of anonymity. After the deposits, the attacker let the pool percolate for a day or two. Then, using a fresh withdrawal address funded from a separate source (probably a small exchange deposit), they claimed the full 2,290 ETH in one go. The withdrawal address now holds a clean balance, unlinked to the original theft. The attacker can then send that ETH to a compliant exchange, where they will attempt to cash out.
But here is the rub: the attacker is not as anonymous as they think. Every deposit into Tornado Cash creates a timestamped footprint. The analytics firms are not just watching the pool; they are watching the edges. They know the approximate time windows of the deposits and withdrawals. They can correlate the withdrawal address’s later behavior—like a deposit to a centralized exchange—if the exchange has a KYC record. The attacker’s only hope is to withdraw to a chain that offers better privacy (like Monero) or to a non-custodial wallet that they never link to their real identity. But the urge to cash out is strong. The temptation to convert ETH into fiat or stablecoins on a platform like Binance or Coinbase is the point of failure.
I saw this pattern during the 2020 DeFi Summer, when I retreated to a cabin outside Seattle to study Yearn Finance’s vault composability risks. While others chased yields, I calculated the systemic contagion potential of leveraged stablecoins. I published a whitepaper on “Ethical Leverage” that was largely ignored. But the lesson stuck: leverage without ethics is a house of cards. Similarly, anonymity without accountability is a sanctuary for theft. The attacker is not just using a tool; they are exploiting a public good that was designed for political dissidents and ordinary privacy seekers. By doing so, they poison the well for everyone.
In the chaos of DeFi, I found my silence. But that silence is now being weaponized.

Contrarian: The Attacker Is Actually Helping the Regulators
Here is the counterintuitive truth: the attacker’s repeated use of Tornado Cash is a gift to the enforcement narrative. Every time a headline reads “Hacker launders $4M through Tornado Cash,” the OFAC’s argument that “privacy tools = crime tools” gains weight. The attacker is inadvertently proving the regulators right. They are handing them the evidence they need to justify broader sanctions, more aggressive chain analysis, and tighter controls on all privacy protocols.
But this is a perverse feedback loop. The more the attacker uses Tornado Cash, the more the protocol becomes a honeypot for surveillance. The more the regulators clamp down, the more desperate attackers become to use the only tool that still works. The real loser is the legitimate user—the journalist in an authoritarian country, the artist who wants to sell NFTs without doxxing themselves, the small business owner who values financial privacy. They are collateral damage in a war between criminals and the state.
We minted souls, not just tokens. But the soul of this ecosystem is being corroded by the very tools we built to protect it.
The attacker’s strategy is also flawed from a money-laundering perspective. Using the same mixer twice is a behavioral signature. Sophisticated analytics firms like Elliptic and TRM Labs have built time-series clustering models that can link these two events. They can identify the withdrawal address by analyzing the exact timing of the deposits and the subsequent withdrawal. The attacker may have thought they were smart, but they just created a two-point pattern that makes them more traceable, not less.
Takeaway: The Fork in the Road
To build in public is to trust the void. We are building a financial system that is transparent, permissionless, and global. But transparency without ethics is a ledger of exploitation. The attacker’s $4.39 million move is a test: will we design privacy tools that are accountable, or will we let them become the exclusive domain of criminals?

I believe the answer lies in selective disclosure protocols—zero-knowledge proofs that allow users to prove they are not a sanctioned entity without revealing their full transaction history. Projects like Railgun and Nocturne are exploring this path, but they need adoption. Regulation is not going away, and it should not. The goal is to build compliance into the software, not to fight the state.
Truth emerges when the ledger is transparent. But so does justice. The attacker’s remaining $9.8 million will likely move again. I will be watching. And I hope the analytics firms are too.

Will we build a world where the individual is sovereign and the community is safe? Or will we let the ghosts in the mixer dictate the narrative? The choice is ours—and it is urgent.