Advertisement
Share this article

Thousands of Ether From Ronin Exploit Moved to Tornado Cash, Data Show

More than 2,001 ether were moved Monday from addresses connected to the $625 million exploit, with about 70% passing to the privacy tool in the early hours, on-chain data show.

On-chain data show ether from the Ronin exploit has been moved to Tornado Cash. (Seksan Mongkhonkhamsao/Getty)
On-chain data show ether from the Ronin exploit has been moved to Tornado Cash. (Seksan Mongkhonkhamsao/Getty)

The exploiter behind Ronin’s unprecedented $625 million bridge attack from last week apparently moved some 1,400 ether (ETH) to privacy tool Tornado Cash on Monday morning during Asia hours, and then the remaining 600 ETH during European hours, on-chain data connected to the exploit’s addresses show.

  • The main Ethereum address associated with the exploit sent more than 2,001 ETH in two transactions to a different address – labeled “Ronin Bridge Exploiter 8” on the tracking tool Etherscan – in early Asian hours, the data shows.
  • Some 1,400 ETH were then sent to Tornado Cash over 14 transactions, the data shows. The moved ether was valued at over $4.9 million at writing time. The remaining 600 ether, valued at $2 million, was moved to Tornado Cash in European hours, the data show.
  • The main wallet that holds stolen funds still has in excess of 173,000 ETH, valued at over $607 million, at writing time.
  • Tornado enhances the privacy of transactions by breaking the on-chain link between a source and a destination address. This allows exploiters and hackers to mask their addresses while withdrawing illicitly gained funds.
  • Several thousands of ether had previously been moved to other wallets, data apparently shows. Those transactions ranged from 1 ETH to over 10 ETH.
  • Ronin Network was hit by a $625 million exploit last week that affected Ronin validator nodes for Sky Mavis, the publisher of the popular Axie Infinity game, and the Axie DAO.
  • The attacker “used hacked private keys in order to forge fake withdrawals” from the Ronin bridge across two transactions, as seen on Etherscan, Ronin said in a blog post on Substack.
  • Investigations are underway, with all former Sky Mavis validators said to have been replaced.

See also: So You’ve Stolen $600M. Now What?

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

UPDATE (April 4, 13:16 UTC): Updates story to reflect additional movement of ether out of Ronin Bridge Exploiter 8 address during European hours.

Shaurya Malwa

Shaurya is the Co-Leader of the CoinDesk tokens and data team in Asia with a focus on crypto derivatives, DeFi, market microstructure, and protocol analysis.

Shaurya holds over $1,000 in BTC, ETH, SOL, AVAX, SUSHI, CRV, NEAR, YFI, YFII, SHIB, DOGE, USDT, USDC, BNB, MANA, MLN, LINK, XMR, ALGO, VET, CAKE, AAVE, COMP, ROOK, TRX, SNX, RUNE, FTM, ZIL, KSM, ENJ, CKB, JOE, GHST, PERP, BTRFLY, OHM, BANANA, ROME, BURGER, SPIRIT, and ORCA.

He provides over $1,000 to liquidity pools on Compound, Curve, SushiSwap, PancakeSwap, BurgerSwap, Orca, AnySwap, SpiritSwap, Rook Protocol, Yearn Finance, Synthetix, Harvest, Redacted Cartel, OlympusDAO, Rome, Trader Joe, and SUN.

Shaurya Malwa